Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill declares only the Bash tool but does not explicitly declare permissions, even though its documented behavior requires network access to call the Neta API and likely access to sensitive input such as an API token. This mismatch weakens sandboxing and user awareness because the runtime capabilities exceed what is transparently declared, increasing the risk of unintended data exposure or policy bypass.
