Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill advertises and demonstrates network-capable behavior, including calls to external AI endpoints and Feishu message delivery, but does not declare corresponding permissions. Hidden or undeclared network use reduces user visibility into where sensitive contract data may be sent and weakens platform policy enforcement. Because the content handled is contractual and often confidential, the omission is security-relevant rather than a harmless documentation gap.
