Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill documentation explicitly states that user search queries are sent to an external API, but the skill declares no corresponding permissions despite requiring Python scripts that perform network access. This creates a transparency and consent problem: users and hosting platforms may assume the skill is local-only while it actually exfiltrates input to a remote service, which is especially risky if users include secrets, internal project names, or sensitive prompts in queries.
