Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill is invocable and explicitly states its logic is implemented in `do.py`, which performs file reads from `data.json`, but the manifest does not declare any tool scope such as `permissions` or `allowed-tools`. This creates an authorization and transparency gap: reviewers and platforms cannot clearly constrain or validate the file access the skill relies on, which can lead to overbroad runtime access or policy bypass depending on the host environment.
