Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 81% confidence
- Finding
- The skill uses environment secrets and makes external network calls, but it does not declare corresponding permissions or user-visible boundaries. That weakens platform-level governance and informed consent, making it easier for an agent to transmit user queries, handles, or API-backed results off-platform without clear review.
