Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill documentation instructs the agent to run a bundled Python script that fetches official FEHD JSON endpoints, which implies network access, yet no permissions are declared. This creates a trust and policy gap: agents or reviewers may believe the skill is offline-only when it can actually make outbound requests, reducing transparency and weakening security controls around network use.
