Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill invokes a Node.js script that reads environment variables containing bearer tokens and performs outbound network requests, but the skill declares no explicit permissions for those sensitive capabilities. This creates a transparency and policy-enforcement gap: a caller or platform may treat the skill as lower risk than it really is, while the script can still access secrets and transmit local document contents to a remote API.
