Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill advertises offline/mock operation but also includes live Spacebase1 commands, credential variables, and Python/client examples indicating external network interaction, while the declared allowed-tools omit any explicit network-capable permission. This mismatch can mislead operators and policy enforcement layers about the skill’s true capability surface, increasing the chance of unintended outbound connections or review bypass.
