Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 96% confidence
- Finding
- The skill requires network access and use of an API key from environment or a local .env file, but it declares no permissions or capability boundaries. This creates a transparency and least-privilege problem: an agent may transmit user-generated content and credentials to an external service without an explicit permission declaration, increasing the risk of unintended data disclosure.
