Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill advertises and instructs use of an external API token and invokes a script that necessarily makes outbound network requests, but the skill metadata does not declare network permissions. This mismatch is dangerous because it obscures the skill's true capabilities from reviewers and users, reducing transparency around data egress and token handling.
