Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 79% confidence
- Finding
- The skill clearly relies on multiple outbound network-backed tools and APIs, but the skill metadata does not declare corresponding permissions. Undeclared network capability weakens security review and policy enforcement because consumers may invoke a skill that can reach external services without that access being explicitly surfaced. In this context the destinations appear documentation-related and public, so the issue is more about transparency and control than obviously malicious behavior.
