Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill describes executable CLI behavior that uses environment variables for secrets, performs network requests to external WeChat APIs, and writes a local token cache file, but it declares no permissions. That mismatch is a real security issue because users and hosting agents are not given an explicit trust boundary for secret access, outbound communication, or filesystem writes, which can lead to unintended secret exposure, unauthorized API actions, or policy bypass in permission-gated environments.
