Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill advertises and depends on network-capable behavior (`curl`, a local SearXNG HTTP endpoint, and search operations) but does not declare corresponding permissions. This creates a transparency and policy-enforcement gap: operators may approve the skill believing it has no sensitive capabilities, while it can still send queries over the network and potentially expose sensitive search terms or reach unintended endpoints if the implementation changes.
