Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill advertises use of network-capable functionality (`exec` for API calls and `web_search`) but does not declare any explicit tool scope such as `permissions` or `allowed-tools`. This creates an authorization ambiguity where a host agent may grant broader-than-intended capabilities, increasing the risk of unintended outbound requests, data exfiltration, or tool misuse if the skill behavior expands or is prompt-injected.
