Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill instructs users to run local Python scripts that read credentials from environment variables and make outbound network requests, but the skill declares no corresponding permissions or capability disclosures. This creates a transparency and governance gap: an agent or user may invoke code with access to secrets and external services without an explicit permission model, increasing the risk of unintended credential exposure or unauthorized network use.
