Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill documentation declares no permissions, yet it explicitly instructs use of environment variables for credentials and network access to remote eBusy instances. This creates a transparency and policy-enforcement gap: agents or reviewers may underestimate that the skill handles secrets and performs outbound authentication requests, increasing risk of unintended secret exposure or overly broad execution in a runtime that relies on declared permissions.
