Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill advertises that no API key is needed and its documented usage invokes Node.js scripts that scan Binance Futures and monitor coins, which implies outbound network access. If the skill does not declare required network permissions, users and platforms may be misled about the capability surface, reducing transparency and weakening permission-based security review. In this context, network access is expected for the stated functionality, which makes the issue less suspicious than hidden exfiltration logic, but it is still a real security and governance problem.
