Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill instructs the agent to access an environment API key, call an external network service, and write local files, but it does not declare these capabilities or permissions. Hidden or undeclared capability use weakens user oversight and sandbox policy enforcement, especially because the workflow includes exfiltration-relevant operations such as sending user-derived queries to a third-party API and persisting outputs to disk.
