Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill documentation describes running a local HTTP-based secret collection flow, which is a network capability, but no corresponding permission declaration is present. Undeclared network behavior is dangerous because it prevents informed consent and can cause the agent to expose a listening service unexpectedly in environments where network access should be tightly controlled.
