Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill exposes clear network-capable behavior and instructions for fetching arbitrary URLs, but no explicit permissions boundary is declared. In an agent ecosystem, undeclared network capability weakens user awareness and policy enforcement, increasing the chance that the skill is used to access external systems unexpectedly.
