Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill documentation shows clear network-enabled behavior through calls to the third-party TikHub API, but no corresponding permission declaration is present. This creates a transparency and governance gap: users and platforms may not realize the skill sends requests externally, which can lead to unintended data disclosure and weakened policy enforcement.
