Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill performs networked API operations, reads configuration from a .env file, and can write exported dashboard files, but it does not declare any permissions or equivalent trust boundaries in the skill metadata. This creates a transparency and consent problem: a caller may invoke the skill without realizing it can access secrets, contact external services, and write to disk, which increases the risk of unintended data exposure or unsafe file writes.
