Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill clearly performs outbound network access to fetch WeChat article content, yet no explicit permissions are declared in the manifest. That creates a transparency and governance gap: callers and policy engines cannot accurately reason about the skill’s capabilities, and the undocumented network access could be abused or expanded without clear review.
