Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill clearly relies on outbound network access to query the CoinGecko API, but the documentation does not declare that capability as a permission. Undeclared network use weakens transparency and policy enforcement, making it easier for a skill to access external services without clear user or platform awareness, though the stated purpose here is consistent with the skill's function rather than overtly malicious.
