Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill advertises execution of a Python script that queries a network API, while the metadata declares no environment requirements or permissions related to network access. This mismatch can bypass user/operator expectations and review controls, making hidden or under-declared outbound/internal connectivity easier to abuse.
