Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill declares only `tools: Bash` but its documented usage explicitly requires a Neta API token and invokes a remote image generation service, which implies network access. Undeclared network capability is a real security concern because it can mislead reviewers and users about what data may leave the environment, especially when prompts or tokens may be transmitted to a third party.
