Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill documentation indicates it invokes a Python script that calls the OKX public market API, which is a network-capable action, yet no corresponding permission is declared in the manifest metadata. Undeclared network access weakens transparency and policy enforcement, making it harder for users or the platform to understand and constrain what the skill can do.
