Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill declares only Bash as an allowed tool, but the documented execution path invokes a Python script that almost certainly performs outbound network access to geocode cities and fetch weather data. If network capability is not explicitly declared, operators and policy controls may underestimate what the skill can do, reducing transparency and weakening permission-based review.
