Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill declares only `allowed-tools: Bash`, but the documented behavior clearly relies on network access to government APIs and file writes/reads for caching in the system temp directory. This mismatch weakens policy transparency and reviewability, making it easier for a skill to perform capabilities operators did not explicitly approve.
