Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill advertises use of environment variables for API credentials and a Python client that communicates with the Tencent IMA API, which implies environment and network access, yet no explicit permissions are declared. This mismatch is dangerous because users and host systems cannot accurately assess the skill's runtime capabilities, increasing the risk of unexpected credential access or outbound communication without informed consent.
