Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill documentation indicates use of a Neta API token and a Node script that calls an external service, but the manifest only declares `tools: Bash` and does not clearly declare network capability/permissions. This mismatch can cause users or host systems to underestimate what the skill can do, especially because it handles secrets and sends prompts to a third-party API.
