Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 82% confidence
- Finding
- The skill explicitly relies on environment variables such as R2_UPLOAD_CONFIG, R2_DEFAULT_BUCKET, and R2_DEFAULT_EXPIRES, but no declared permissions are shown for environment access. Undeclared access to configuration and environment state weakens transparency and consent, and in a credential-handling storage skill this matters because env/config values can contain sensitive paths or secrets.
