Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill explicitly instructs users to run shell and Python scripts that perform outbound network access to multiple external services, yet it declares no permissions. This creates a transparency and policy enforcement gap: hosts or users may not realize the skill can execute code and make network requests, which increases risk from supply-chain changes, unexpected data exfiltration paths, or unsafe execution in restricted environments.
