Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill documentation indicates the capability to read environment variables for API credentials and perform outbound network requests, but it does not declare any explicit tool scope or permission boundary. In an agent environment, this weakens least-privilege controls and can allow the skill to be invoked with broader access than users or orchestrators expect, increasing the risk of credential misuse or unintended external data transmission.
