Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 96% confidence
- Finding
- The skill explicitly requires internet access and instructs users to download data from external NASDAQ and Yahoo Finance endpoints, yet it declares no permissions. Missing permission declarations create a trust and policy-enforcement gap: users or platforms may approve the skill without realizing it can make outbound network requests and ingest untrusted remote content. In a skill ecosystem, undeclared network capability is security-relevant even if the stated use case is legitimate.
