Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill invokes a Python script that fetches live data from an external site, which implies network access, but the skill metadata does not declare any explicit tool scope such as permissions or allowed-tools. This creates a policy and containment gap: an agent may execute network-capable code without an auditable, least-privilege declaration, increasing the risk of unexpected outbound requests or future capability creep.
