Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill clearly requires network access to query immowelt and execute a Python script, but the metadata only declares a binary requirement and does not declare corresponding permissions. Undeclared network/code capabilities reduce transparency and can bypass user or platform expectations about what the skill is allowed to do, which is a real security and governance issue even if the described use case is legitimate.
