Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill explicitly instructs use of outbound network access to a third-party API and execution of a bundled Python script, but it does not declare any tool scope such as permissions or allowed-tools. In agent runtimes that rely on manifest-scoped permissions, this can lead to overbroad tool availability, unclear trust boundaries, and accidental execution with more capabilities than the skill actually needs.
