Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill includes code that performs outbound network access to Yahoo Finance and CoinGecko, but no declared permissions are shown. Undeclared capabilities weaken the trust boundary for users and host platforms because the skill can transmit requests externally without transparent permission scoping.
