Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill advertises Bash usage and an external API token, but the manifest does not declare the network capability even though the described behavior clearly requires outbound requests. This creates a transparency and policy-enforcement gap: users and hosting systems may approve or run the skill without realizing it can transmit prompts and credentials to a remote service.
