Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill clearly relies on network access to a remote werewolf server, yet the manifest does not declare that capability or make the data flow explicit up front. Undeclared network behavior reduces transparency and consent, making it easier for user prompts and gameplay metadata to be sent off-device without users or platform policy checks fully accounting for it.
