Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill instructs the agent to perform live network access to arbitrary `mp.weixin.qq.com` article URLs via a local Python script or browser tool, but the skill declares no corresponding permissions. This creates a permission-model mismatch: the agent may fetch untrusted external content without explicit user-visible authorization boundaries, increasing SSRF-like abuse surface, privacy risk, and unintended outbound requests.
