Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill explicitly relies on sensitive environment data such as GITHUB_TOKEN and GITHUB_ORG, but no permissions are declared in the skill manifest. That creates a trust and review gap: operators cannot easily see that the skill consumes credentials, and runtimes may grant broader access than intended. In a security-sensitive automation context, undeclared credential usage increases the risk of accidental secret exposure or misuse.
