Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill performs outbound network activity to Cloudflare speed test endpoints, but the manifest does not declare any corresponding permission or network capability. Undeclared network access weakens transparency and policy enforcement, making it harder for users or the host platform to understand, review, and restrict what the skill can do.
