Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill explicitly relies on an external public API (`fund.eastmoney.com`) and therefore has network capability, but the metadata declares only a local binary requirement and no corresponding permission. Undeclared network access reduces transparency and can bypass policy or review expectations, creating risk around data exfiltration, dependency on untrusted remote content, and unexpected outbound requests.
