Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill declares no permissions while instructing use of environment variables, reading and writing `~/.upkuajing/.env`, and making networked API calls. This mismatch reduces transparency and weakens consent boundaries, making credential handling and external data access more dangerous because users and platforms cannot accurately evaluate what the skill can do.
