Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill describes and facilitates outbound network access via the Python requests library and a configurable RAG_URL, but no explicit permissions are declared. That mismatch is a real security issue because users or hosting platforms may not realize the skill can send data off-system, including memory contents passed to save_memory(). In this context the capability is functionally aligned with the stated purpose, so it appears benign rather than deceptive, but it still increases data exfiltration and SSRF risk if misconfigured or abused.
