Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill explicitly instructs the agent to perform outbound web requests through multiple third-party fetching services and browser-based retrieval, yet no permissions are declared. Undeclared network capability weakens policy enforcement, auditability, and user awareness, and can enable unintended access to arbitrary external URLs or data exfiltration pathways through external services.
