Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill uses a local Node CLI and performs outbound network access, but the manifest does not declare an explicit tool/permission scope. That weakens least-privilege enforcement and makes it harder for a host to constrain what the skill is allowed to do, especially if the underlying script behavior changes later. In this context the documented behavior is read-only market-data access, which reduces severity, but the undeclared capability gap is still a real security issue.
