Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 97% confidence
- Finding
- The skill invokes Python scripts, reads environment variables like QICHACHA_TOKEN, performs network access to external data sources, and generates .docx files, yet declares no permissions. This creates a mismatch between stated and actual capabilities, undermining sandboxing and user consent expectations and potentially allowing sensitive file, network, or environment access without explicit review.
