Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 79% confidence
- Finding
- The skill appears to rely on network access to retrieve Baidu hot-search data, but no explicit permissions are declared in the manifest metadata. Undeclared network capability reduces transparency and can bypass user/operator expectations about what external access the skill requires, increasing review and governance risk.
