Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill clearly documents network access to external Concept2 API endpoints, yet the manifest shown in the file does not declare any permissions or equivalent capability boundary. That mismatch weakens reviewability and user consent because a caller may not understand that the skill will transmit authentication tokens and workout data off-platform.
