Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill declares only `Bash`, but its documented usage invokes a Node script that sends prompts and optional reference identifiers to the external Neta API, indicating network-capable behavior that is not transparently declared. This can mislead users and platforms about the skill's actual data flows, reducing informed consent and weakening permission-based controls.
