Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill documentation exposes network-dependent functionality and external API usage, but no explicit permissions declaration is present. This can undermine user and platform transparency by allowing a skill to transmit user queries, purchase selections, and order identifiers to a third-party service without clear upfront capability disclosure.
