Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill invokes external CoinGecko API calls but does not declare any permissions, creating a mismatch between documented behavior and the platform's security model. Undeclared network access reduces transparency, weakens reviewability, and can allow a seemingly simple skill to exfiltrate prompts or metadata if the implementation changes or is replaced later.
