Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill requires access to the `GUAIKEI_API_TOKEN` environment variable, but no explicit permission declaration is surfaced alongside that capability. Hidden or undocumented access to secrets increases the risk that callers invoke the skill without understanding that sensitive credentials are being consumed. In this context the risk is somewhat reduced because the env var is openly described in the markdown, but the static finding is still valid if the platform expects formal permission declaration rather than prose-only disclosure.
