Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill declares only `tools: Bash` but its documented usage clearly sends prompts and tokens to an external Neta API, which implies network access that is not explicitly declared. This weakens permission transparency and can mislead users about data egress, especially because user prompts and API tokens may be transmitted to a third party.
