Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill declares no permissions, yet its documented behavior clearly requires network access to Baidu APIs and local file creation for CSV/JSON outputs. This mismatch can mislead reviewers and users about the skill's actual capabilities, reducing informed consent and making unsafe execution more likely.
