Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill explicitly instructs running a bundled Python script that queries external KMB/LWB, Citybus, and MTR endpoints, so network capability is clearly present while no permission declaration is shown. This is not inherently malicious in a transport-ETA skill, but undeclared network access reduces transparency and can surprise the host environment or users, especially if permission gating or review relies on manifest declarations.
