Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill clearly requires outbound network access to the Oura API, but the manifest does not declare that capability. Undeclared capabilities weaken review and consent controls because users and platforms cannot accurately understand what the skill can do before execution.
