Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill declares no explicit permissions, yet its documented behavior includes reading local files, accessing environment variables, and making authenticated HTTP requests to an external platform API. This creates an authorization and transparency gap: a caller or platform may treat the skill as low-risk while it can perform state-changing operations and use sensitive credentials.
