Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill declares use of an environment variable token (`GUAIKEI_API_TOKEN`) and command execution via Node.js, but no explicit permission declaration is present in the metadata. This creates a governance gap where reviewers or runtime policy may not clearly understand that the skill accesses secrets, increasing the risk of unintended secret exposure or over-trusting the skill's capabilities.
