Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill invokes a Python script that performs outbound HTTP/TLS analysis and depends on curl, which clearly gives it network capability; it also executes commands from the skill environment, indicating shell/code execution capability. Because these capabilities are not declared in permissions, users and policy systems may underestimate what the skill can do, reducing transparency and weakening sandboxing or approval controls.
