Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 85% confidence
- Finding
- The skill declares no permissions, yet its documented behavior includes reading environment variables, accessing local files under ~/.upkuajing, writing credentials, and calling remote APIs. This mismatch is dangerous because it hides the true privilege and trust boundary from reviewers and users, increasing the chance of unintended credential exposure or paid network actions.
