Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill performs sensitive operations that access environment variables for cloud credentials and initiates outbound network transfers to Tencent COS, yet it declares no permissions. This creates a transparency and consent gap: users or host systems may execute a file-uploading skill without an explicit indication that secrets and local data will be used for remote transmission.
