Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill declares only http and browser requirements, but its documented behavior clearly includes reading, writing, and deleting credential files, using environment-variable overrides, and likely invoking local system functionality. This permission mismatch is dangerous because it hides the true security-sensitive capabilities of the skill from reviewers and users, especially since it handles API secrets and can initiate real purchases.
