Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill appears to rely on network access for market updates, news compilation, and link gathering, but it does not declare any permissions in the manifest. This creates a transparency and policy-enforcement gap: hosts or reviewers cannot accurately assess or constrain what outbound connections the skill may make, increasing the risk of unintended data exfiltration, dependency on untrusted sources, or broader-than-expected network behavior.
