Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill clearly enables outbound network access to a third-party SMS API but does not declare permissions or constraints for that capability. Missing permission declarations reduce transparency and policy enforcement, making it easier for an agent to invoke external actions without explicit governance or user awareness.
