Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill clearly directs use of a network-fetching script across multiple external sources, but no corresponding permissions are declared. This creates a transparency and policy gap: users and host systems may not realize the skill will make outbound requests, increasing the risk of unintended data exposure or unsafe execution in environments that rely on manifest-declared capabilities.
