Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 82% confidence
- Finding
- The skill clearly requires access to sensitive environment data (HF_TOKEN) and reads and writes local files, but it does not declare permissions for those capabilities. This creates a transparency and policy-enforcement gap: users or orchestrators may invoke the skill without understanding that it consumes secrets and modifies the filesystem, increasing the chance of unintended secret exposure or unsafe file access in downstream scripts.
