Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill clearly describes capabilities requiring sensitive operations: reading environment secrets (`${GITHUB_TOKEN}`), network access to GitHub/Slack/local API, and likely file/log output, yet it declares no permissions. This creates a privilege-transparency gap where users or hosting systems cannot accurately evaluate or constrain what the skill can access, increasing the risk of unintended secret exposure, unauthorized issue modifications, or outbound data transmission.
