Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill advertises environment-variable access, project file reads, and arbitrary network access to a runtime-supplied base URL, but it does not declare permissions or trust boundaries. This creates a real security gap because operators and higher-level tooling cannot accurately assess that the skill can read local configuration and send data to external endpoints, increasing the risk of unintended SSRF-like access to internal services or leakage of locally sourced data.
