Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill advertises behavior that uses network access (fetching reference URLs and likely using web search/fact-check services) but does not declare permissions or clearly disclose that external access occurs. Undeclared network capability reduces user awareness and platform policy enforcement, increasing the chance of unexpected outbound requests and data exposure.
