Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 83% confidence
- Finding
- The skill documentation includes network-capable actions such as cloning from GitHub and installing via a package-like command, but there is no explicit permissions model or declaration warning operators that network access is involved. In agent environments, undeclared network behavior weakens trust boundaries and can lead to unreviewed remote content being fetched or installed.
