Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill documentation indicates use of network access and environment variables (for JINA_API_KEY), but no permissions are declared. That mismatch can mislead operators about the skill's capabilities and reduce informed consent, especially because the skill can send arbitrary user-provided URLs and queries to external services. In this context, the risk is increased because the stated purpose is broad web fetching/search, which inherently involves exfiltrating requested targets and possibly sensitive URLs to third-party infrastructure.
