Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill explicitly states it uses native fetch and references an external MCP server plus Apple documentation endpoints, which indicates network access is part of its behavior. Having effective network capability without declared permissions weakens transparency and policy enforcement, making it harder for a host system or user to assess data exfiltration risk or restrict outbound requests.
