Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill explicitly invokes Python scripts that call the external yr.no/MET API, so it does have network capabilities despite no declared permissions. This is not inherently malicious in a weather skill, but the missing permission declaration reduces transparency and weakens policy enforcement, making it easier for users or platforms to underestimate outbound data flow.
