Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 77% confidence
- Finding
- The skill demonstrates shell-based network operations via curl but does not declare corresponding permissions, which weakens the platform's trust and review model. Undeclared execution and network capability can lead to unexpected outbound requests, credential use, and reduced user visibility into what the skill is able to do.
