Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill documentation indicates use of a local HTTP service at localhost:11434, which is a network capability, but no corresponding permission is declared. Undeclared capabilities reduce transparency and can bypass user or platform expectations about what the skill is allowed to access, even if the endpoint is only local.
