Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill explicitly relies on environment variables for credentials and performs authenticated network actions, but it does not declare corresponding permissions. Undeclared access to env and network weakens security review and least-privilege controls, especially because the skill can post content and persists plaintext session cookies, increasing the sensitivity of those capabilities.
