Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill clearly performs outbound network access to YouTube transcript services and can write transcripts to local files, yet the manifest does not declare corresponding permissions. Undeclared capabilities undermine least-privilege review and make it harder for the host to enforce policy or obtain informed user/admin consent, even though the documented behavior appears aligned with the skill's stated purpose.
