Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill explicitly describes reading environment variables for Feishu credentials and performing network operations against Feishu APIs, but it does not declare any permissions. This weakens security review and consent boundaries because an agent or platform operator cannot accurately understand that the skill can access secrets and transmit data externally.
