Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill embeds operational capabilities that rely on environment-injected identifiers and direct network access to an internal API, but it does not declare those permissions explicitly. That creates a trust and review gap: deployers may approve the skill without realizing it can access internal services and tenant/shop-scoped data, increasing the risk of unintended data access, SSRF-style abuse through configurable base URLs, or misuse of privileged context.
