Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 82% confidence
- Finding
- The skill appears to rely on network and environment capabilities, but no permissions are explicitly declared. That creates a trust and review gap: operators cannot easily see that the skill may access external resources or environment-derived data, which can lead to unintended data exposure or unvetted outbound requests. In a competitor-analysis skill, network access is plausible, but undeclared capability use still weakens security transparency and policy enforcement.
