Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill advertises use of an external API token and invokes a Node script that necessarily performs network access, but the manifest does not declare corresponding permissions. Undeclared network capability reduces transparency and can bypass user expectations or platform policy checks, especially when a skill accepts secrets like API tokens and sends prompts to a third-party service.
