Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 85% confidence
- Finding
- The skill advertises Bash execution and an external API workflow, but does not declare permissions despite static analysis detecting network capability. This creates a transparency and consent gap: users and host systems may not realize the skill can send data externally, increasing the risk of unintended prompt or token exposure.
