Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill clearly invokes a local Python script that performs outbound web requests and can consume environment-based proxy settings, yet no permissions are declared. This can mislead operators and downstream policy systems about the skill's true capabilities, reducing oversight for network access and environment-variable use.
