Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill clearly uses sensitive capabilities including environment variable access for a credential, shell execution to invoke Python, and network access to third-party endpoints, but it does not declare explicit permissions for them. This creates a transparency and governance gap: users or hosting platforms may not realize the skill can read secrets and make authenticated outbound requests, increasing the risk of accidental token exposure or misuse if the implementation changes or is audited incompletely.
