Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill explicitly requires sensitive environment variables (`VOLCENGINE_ACCESS_KEY` and `VOLCENGINE_SECRET_KEY`) and instructs the agent to invoke a local script that will consume them, but the skill does not declare explicit permissions governing access to those secrets. This creates a real secret-exposure and overreach risk: an agent using the skill may access cloud credentials without a clear permission boundary, and any future expansion of the script could use those credentials for unintended read or write operations against the user's cloud environment.
