Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill performs outbound network requests to DuckDuckGo endpoints but does not declare any corresponding permission or capability boundary. This creates a transparency and governance gap: users and hosting platforms may not realize that prompts are being sent externally, which can expose sensitive queries and bypass expected review controls.
