Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill documentation describes use of an external API client, video URLs, and polling workflow, which clearly implies network access, yet no permissions are declared. This creates a transparency and governance gap: users or hosting platforms may not realize the skill sends data to third-party services, including user-provided video URLs and prompts.
