Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill exposes network access, environment-variable access, and persistent file writes but does not declare permissions or clearly constrain those capabilities. In a security-sensitive integration that handles API keys, access tokens, and business data, hidden capabilities reduce auditability and can enable unintended data exfiltration or local sensitive-data retention.
