Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill clearly instructs execution of a script that makes outbound network requests to a public API, but it declares no corresponding permissions. Undeclared network capability is a real security and governance issue because reviewers and policy engines cannot accurately assess or constrain what external communication the skill performs, even if the stated use case is legitimate road-condition lookup.
