Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill documentation declares zero configuration and no explicit permissions, yet it describes functionality that depends on outbound network access to a third-party API. This creates a transparency and governance gap: users, platforms, or policy engines may treat the skill as lower risk than it really is, even though it can transmit user-supplied tweet URLs and request metadata off-platform.
