Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 96% confidence
- Finding
- The skill requires access to an environment variable containing a sensitive API token and performs direct HTTP requests, but it does not declare permissions for those capabilities. That mismatch weakens platform trust and review controls because the agent can access credentials and local network services without explicit permission metadata, increasing the chance of unintended data exposure or unauthorized note modification.
