Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill explicitly instructs the agent to run a bundled Python script that fetches real-time quotes from an external source, which implies network access, yet no corresponding permission is declared. This creates a transparency and policy-enforcement gap: operators and sandboxes may not correctly gate or review outbound requests, and users are not clearly informed that external data retrieval occurs.
