Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill explicitly instructs use of a script that fetches live data from aviationweather.gov, which is a network capability, yet the skill metadata shown here does not declare any permissions. Undeclared network access weakens transparency and policy enforcement, and in an agent environment can allow data exfiltration or unreviewed external calls under the guise of normal skill operation.
