Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill advertises and instructs use of capabilities that read configuration and article files, write publishing artifacts, access environment-provided credentials, and make network calls to WeChat, but it does not declare corresponding permissions. That creates a trust and policy gap: a reviewer or runtime may underestimate what the skill can access and transmit, increasing the chance of unintended secret exposure or unauthorized data handling.
