Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 85% confidence
- Finding
- The skill documentation instructs the agent to run a bundled Python script that fetches official parking inventory and live occupancy data, which implies network access, yet no permissions are declared. Undeclared network capability weakens transparency and policy enforcement because reviewers and runtime controls may not realize the skill can contact external resources, even if the stated purpose is legitimate.
