Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill explicitly requires an API key from the environment and instructs execution of a bundled Python script that makes outbound requests to OpenRouter, but it does not declare any permissions despite using env and network capabilities. This creates a security and governance gap: callers may not realize the skill can access secrets and send user/system prompt content to an external service, increasing the risk of unintended secret exposure or data exfiltration.
