Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill invokes network access and reads sensitive configuration from environment variables, but it does not declare permissions to reflect those capabilities. This creates a transparency and policy-enforcement gap: users or hosting systems may approve the skill without realizing it can exfiltrate data over HTTPS or use secrets such as GOOGLE_SCRIPT_TOKEN. The skill context makes this somewhat more sensitive because its stated purpose is to bypass SMTP restrictions, which is a legitimate use case but also closely aligned with data egress and abuse scenarios.
