Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill documentation clearly instructs the agent to invoke a Python script that makes outbound requests to the Umeng Open API, yet no permissions are declared. Hidden or undeclared network capability weakens governance and user/admin awareness, and could allow data exfiltration or unauthorized external access if the skill is installed in a more privileged environment.
