Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill documentation instructs users to run a Python script that performs public HTTP requests, but the skill manifest does not declare any explicit tool scope such as allowed network access. This creates a permission-boundary mismatch: reviewers and execution environments cannot easily verify or constrain the skill’s actual capabilities, which increases the risk of unintended outbound access or future scope creep being introduced without notice.
