Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill documents and directs use of a script that performs outbound network access to the Binance API, but the skill declares no permissions. This creates a transparency and policy gap: users or hosting systems may treat the skill as lower-risk than it actually is, reducing informed consent and weakening sandboxing or review controls.
