Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill advertises and documents code usage that can execute Python and references external URLs, while the manifest shown in SKILL.md does not declare any permissions. This creates a capability transparency problem: users or hosting platforms may assume the skill is passive/documentation-only, but it appears designed to operate with code execution and likely network-relevant behavior, increasing the risk of unintended outbound access or unsafe integration decisions.
