Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill requires access to a sensitive environment variable (`GUAIKEI_API_TOKEN`) but does not declare corresponding permissions or clearly constrain how that secret is handled. This creates a governance gap: the runtime can use external credentials and call a third-party service without an explicit permission boundary, making secret exposure or unauthorized outbound use harder to audit and control.
