Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill clearly performs outbound network operations to Cloudflare and public DNS servers, but the metadata shown in SKILL.md does not declare any corresponding network permission. Even if the behavior is expected for a speed-test skill, undeclared network capability weakens transparency, consent, and policy enforcement, and could allow unexpected external communication in environments that rely on declared permissions.
