Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill explicitly instructs the agent to run a bundled Python script that makes outbound HTTPS requests, but the manifest does not declare any tool scope such as allowed network access. This creates a policy and containment gap: an agent/runtime may permit broader network behavior than intended or fail to enforce least privilege, making later code changes or prompt abuse harder to constrain.
