Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill requires an API key from the environment and explicitly documents outbound calls to a third-party DeepSeek endpoint, but the skill file does not declare permissions for secrets or network access. That mismatch is dangerous because users and hosting platforms may not realize the skill can transmit contract contents and sensitive data to an external service, creating a transparency and data-governance risk rather than a direct exploit primitive.
