Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 85% confidence
- Finding
- The skill uses sensitive capabilities via environment variables for external service credentials (`XUNFEI_APP_ID`, `XUNFEI_API_KEY`, `XUNFEI_API_SECRET`) but does not declare permissions or clearly scope that access. This weakens reviewability and can lead to unintended secret exposure or use of external-network-backed functionality without explicit operator awareness.
