Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill explicitly instructs users to pass an external Neta API token and invokes a Node script that performs network-backed image generation, yet the skill metadata declares only `tools: Bash` and no explicit network permission. This mismatch is a real security issue because it hides outbound network capability from reviewers and users, increasing the chance that secrets are provided to a skill without transparent permission disclosure.
