Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill instructs operators to handle highly sensitive secrets (`app_secret`, verification token, encrypt key) and to deploy a network-accessible callback service, but it declares no permissions or security boundaries. This omission can cause unsafe deployment assumptions, improper review, and overbroad secret/network access in production, increasing the chance of credential exposure or unvetted external connectivity.
