Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill documentation indicates the associated script performs DuckDuckGo web searches, which requires outbound network access, yet no permissions are declared. This creates a transparency and policy-enforcement gap: users or hosting platforms may assume the skill is local-only while it can transmit queries to external services, potentially exposing sensitive input and bypassing expected approval controls.
