Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 80% confidence
- Finding
- The skill declares no permissions in metadata, yet its documented behavior and referenced code require network access to fetch market data. This creates a transparency and governance gap: users and hosting platforms cannot accurately assess or constrain what the skill will do, which increases the risk of unexpected outbound connections and weakens trust boundaries.
