Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill declares substantial capabilities—environment variable access, filesystem read/write, and network access to Feishu and Gitea—but does not expose any explicit permissions model or scope limitations in the skill declaration. This creates a real security issue because operators and reviewers cannot easily tell what the skill is allowed to access, increasing the risk of over-privileged execution, secret misuse, unintended repository writes, or broad data exfiltration if the implementation or downstream prompts are compromised.
