Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill declares only the Bash tool, but its documented usage clearly invokes a Node script that calls the external Neta API using a user-supplied token, which implies network access. Undeclared network capability is risky because users and enforcement systems may not realize the skill can transmit prompts and credentials to a third-party service, reducing transparency and weakening permission controls.
