Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill documentation describes network-capable behavior such as querying multiple exchanges and sending Feishu/Telegram alerts, but the skill metadata does not declare corresponding permissions. Missing permission declarations weaken transparency and policy enforcement, making it easier for a skill to perform outbound communication that users or a platform may not expect.
