Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 81% confidence
- Finding
- The skill performs network access to a third-party API but does not declare that capability or any equivalent permission boundary. Undeclared external access reduces transparency, makes review harder, and can cause users or hosting frameworks to send data off-platform without clear consent or policy enforcement.
