Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill declares runtime requirements for an environment variable and executes a Python script that calls an external API, but it does not clearly declare corresponding permissions or provide an explicit data-flow warning. This creates a transparency and policy-enforcement gap: an agent may access secrets and transmit user-specified business data externally without a clearly bounded permission model.
