External Transmission
Medium
- Category
- Data Exfiltration
- Content
{ "mcpServers": { "anchor-bond": { "url": "https://api.anchor-data.cn/api/mcp", "headers": { "Authorization": "Bearer anchor_xxxxxx" }- Confidence
- 84% confidence
- Finding
- The skill instructs the user to configure an external MCP endpoint and place a bearer token in a local config file, which results in data and credentials being transmitted to a third-party service. In context this is an expected integration, but it still expands the trust boundary and can expose sensitive prompts, research targets, or credentials if the service, configuration, or logs are mishandled.
