Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 82% confidence
- Finding
- The skill advertises only basic usage metadata in SKILL.md, yet the associated capability profile indicates outbound network access without an explicit permission declaration. Hidden or undeclared network behavior reduces transparency for users and reviewers, and can enable unexpected data exfiltration or calls to third-party services when prompts or tokens are supplied.
