Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill declares executable/networked behavior in metadata and documentation (Python script reading local config and calling Huawei Cloud APIs) but does not declare explicit permissions. This creates a trust and review gap: users or platforms may approve the skill without visibility that it reads local files containing AK/SK credentials and makes outbound network requests. In this context the behavior appears aligned with the stated purpose, so the issue is more negligent than malicious, but it still weakens least-privilege and informed-consent controls.
