Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 85% confidence
- Finding
- The skill requires a sensitive environment variable (`GUAIKEI_API_TOKEN`) and invokes external tooling/API access, but does not declare explicit permissions. This creates a transparency and governance gap: operators and higher-level agents may not realize the skill can exfiltrate user-supplied URLs and retrieved data to a third-party service. In this context the behavior appears functional rather than overtly malicious, but the missing permission declaration weakens consent and review controls.
