Lp1
High
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The script performs outbound network access to the Open-Meteo API, but the skill manifest declares only shell:exec permission. This is a real permission-model mismatch because the code can transmit user-supplied location data externally without that capability being explicitly declared, reducing transparency and weakening policy enforcement.
