Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill documents network-capable behavior by invoking a CLI that queries external on-chain/address data, but it does not declare any explicit tool scope such as allowed tools or permissions. This creates a policy and containment gap: an agent runtime may permit broader-than-intended network access or make unsafe assumptions about what the skill is authorized to do, reducing reviewability and increasing the chance of misuse if the implementation changes or is replaced.
