Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill invokes shell and performs outbound network access to scrape BCV, call Binance P2P, and potentially use a fallback API, but the manifest does not declare corresponding permissions. This creates a transparency and policy-enforcement gap: reviewers and runtime controls may not accurately understand or constrain the skill’s real capabilities, increasing risk if the implementation changes or is abused.
