Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill declares it will send user prompts to a local ComfyUI endpoint over HTTP, which is a network-capable action, yet no permissions are declared. Undeclared network capability weakens transparency and consent boundaries, and because the endpoint is localhost it may expose or drive a locally running service the user did not expect the skill to access.
