Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill documentation indicates capabilities to read environment variables and local files in order to locate `.longbridge_config`, but it does not declare corresponding permissions. Undeclared capability use weakens transparency and consent controls, and can lead to accidental access to sensitive credentials such as API keys and access tokens.
