Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill invokes an external image-generation API and requires a user-supplied token, which implies outbound network access, but the manifest does not declare corresponding permissions. This creates a trust and review gap: users may install a skill believing it has limited capabilities while it can transmit prompts and secrets to a remote service.
