Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill invokes an external API and therefore has network capability, but the manifest does not declare that permission. This creates a trust and review gap: users and platform security controls may underestimate what the skill can do, including transmitting prompts, tokens, or referenced image identifiers to a third party.
