Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill performs outbound network access to a third-party API but does not declare any corresponding permission or capability boundary. This is dangerous because it hides data egress behavior from reviewers and users, especially when the transmitted value is an IMEI tied to a physical device and its location lookup.
