Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill declares only a Bash tool but, per the analysis, also performs network access without explicitly declaring that capability. Hidden or undeclared network behavior reduces transparency and can expose prompts, tokens, or generated content to external services without the user understanding the full trust boundary.
