Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill clearly relies on outbound network access to `api.rhdxm.com`, but the metadata declares only a binary requirement and no corresponding network permission/capability. This mismatch can mislead users and policy engines about what the skill does, reducing informed consent and weakening sandbox/approval controls around data egress.
