Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill documentation demonstrates network-capable behavior such as loading images from URLs and making API requests, but the skill metadata does not declare any corresponding permission or capability. This creates a transparency and policy-enforcement gap: an agent or reviewer may assume the skill is local-only while it can transmit data externally.
