Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill performs sensitive actions including reading environment variables, storing authentication cookies on disk, invoking shell commands, and making network requests, yet the manifest shown in SKILL.md declares no explicit permissions or trust boundaries. This is dangerous because users and the hosting platform cannot accurately assess or constrain the skill's access, and the skill handles a high-value credential (`kimi-auth`) that could expose account data if misused or improperly stored.
