Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 78% confidence
- Finding
- The skill requires access to a sensitive environment variable (`GUAIKEI_API_TOKEN`) but does not declare permissions in a structured way, creating a transparency and governance gap. In agent platforms, undeclared secret usage can bypass user/admin expectations and increase the risk of accidental secret exposure, unauthorized external calls, or unsafe deployment assumptions.
