Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill documentation explicitly describes outbound HTTP requests to multiple third-party domains and local file handling, yet no permissions are declared. This creates a transparency and governance gap: users or hosting platforms may execute a skill with broader capabilities than its manifest communicates, increasing the risk of unexpected network egress in sensitive environments.
