Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 83% confidence
- Finding
- The skill requires access to an API token via environment variables, but no explicit permission declaration or user-facing permission framing is present. This creates a transparency and governance gap: agents may invoke a networked capability using sensitive credentials without clear policy scoping, increasing the risk of unintended external data access or token misuse.
