Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill clearly instructs the agent to perform outbound HTTP requests, yet no explicit permissions model is declared. This creates a governance gap where network access exists without transparent declaration or least-privilege constraints, making abuse or accidental data exfiltration harder to detect and review.
