Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill clearly describes and depends on network access to query the Open-Meteo API, but the manifest metadata only declares a binary requirement and does not declare the network capability. This creates a permissions/documentation mismatch that can mislead users and security tooling about the skill's real behavior, reducing transparency and informed consent.
