Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill instructs the agent to run a Python script that uses network access to query the GitHub Search API and can read a GitHub token from the environment, yet the skill declares no permissions or safety constraints. This creates a real transparency and policy-enforcement gap: an agent may perform outbound requests and access sensitive environment data without explicit user-facing authorization boundaries.
