Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill documentation indicates capabilities to invoke Python, shell, and outbound network access, but no permissions are declared to make those capabilities explicit. This can cause users or a hosting platform to underestimate the skill's ability to contact arbitrary external URLs and send request data off-system.
