Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill documentation indicates reliance on an environment variable (`QUIVER_API_KEY`) and execution of a local Python script, but it does not declare an explicit tool scope such as `permissions` or `allowed-tools`. In agent environments, this can cause the skill to run with broader-than-intended access to environment data, increasing the chance of secret exposure or unauthorized capability use if the script or surrounding workflow is modified or abused.
