Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill instructs the agent to fetch content from external mp.weixin.qq.com URLs via a bundled script, which is a network-capable behavior, but the skill metadata does not declare that permission. Undeclared network access weakens policy enforcement and auditability, and could lead to unexpected outbound requests or broader misuse if the script is modified or invoked on attacker-controlled inputs.
