Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill declares no permissions, but its documented invocation runs Python and makes an outbound HTTPS request to a third-party endpoint. This mismatch is a real security issue because the host/user may rely on the manifest to understand or enforce capabilities, and undeclared network and shell execution expand the trust boundary to remote content and local code execution.
