Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill explicitly instructs the agent to access a networked ESP32-CAM endpoint, but no corresponding permission declaration is documented. Hidden or undeclared network access reduces transparency and weakens policy enforcement, making it easier for the skill to perform external communication without informed user or platform approval.
