Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill instructs the agent to run a Node.js script that performs outbound network access to the PullPush API, but the skill metadata does not declare any tool scope such as permissions or allowed-tools. This creates a mismatch between documented capabilities and actual behavior, reducing policy enforcement and reviewability; if similar patterns are reused, an agent may make unintended external requests or exfiltrate user-supplied data to third-party services without explicit authorization.
