Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill documents use of environment variables such as GLM_API_KEY but does not declare corresponding permissions or clearly constrain access to sensitive runtime capabilities. This can lead to unexpected secret exposure or capability expansion, especially because the skill spawns other agents and forwards prompts/data across runtimes.
