Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill explicitly instructs the agent to fetch data from an external Google Trends RSS endpoint, which is a network capability, but no corresponding permission is declared. Undeclared network access weakens policy enforcement and user/operator awareness, and can allow a skill to make external requests without the expected security review or runtime controls.
