Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill declares only `allowed-tools: [exec]`, but its manifest and instructions clearly require environment-variable access and network activity for scanning target IPs and pushing data. This mismatch reduces transparency and weakens policy enforcement, making it easier for a caller or runtime to grant broader capabilities than users may realize.
