Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill declares and demonstrates live network payment capabilities via curl and remote API endpoints, but the metadata shown does not declare corresponding permissions. In a payment-execution skill, this mismatch is dangerous because it can obscure the real capability surface from users or policy engines and enable outbound financial actions without explicit permission review.
