Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill explicitly instructs the agent to invoke a shell-capable network utility (`ping-tool`/`ping`) but declares no permissions. This creates a mismatch between the documented behavior and the declared security model, which can lead to undeclared command execution and network probing against user-supplied hosts.
