Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill declares access to an environment variable via `primaryEnv: PROXY_TOKEN` and describes sending user queries to external proxy-backed APIs, but no explicit permissions model is documented. This creates a real least-privilege and transparency issue: operators and users cannot clearly audit what network/env access the skill requires, and a proxy token could be misused if the skill or backend behavior changes.
