Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill clearly instructs users to make authenticated network requests to an external service and to install backend/UI components that manage OAuth connections, yet no declared permissions are present. This creates a transparency and policy-enforcement gap: operators and any permission model cannot accurately assess or constrain the skill's network behavior, which is especially relevant because it handles API keys and SaaS integrations.
