Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill advertises networked and environment-sensitive capabilities without declaring permissions or constraints, which reduces transparency and weakens policy enforcement. In practice, this can let an agent invoke external services, fetch remote content, or access runtime configuration in ways users and orchestrators may not expect.
