Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill explicitly instructs the agent to make outbound HTTP requests to an external API, but the skill metadata does not declare corresponding network permissions. This mismatch weakens transparency and policy enforcement, making it harder for a platform or reviewer to reason about the skill's external data flows and increasing the risk of unintended data exposure if user input is sent to the remote service.
