Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 82% confidence
- Finding
- The skill clearly performs external network operations against Apify, Gemini, and Facebook Graph API, yet it does not declare permissions or explicitly scope those capabilities. This makes the skill harder to review and increases the chance of unintended data egress or execution in contexts where network use was not expected.
