Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 82% confidence
- Finding
- The skill advertises itself as invocable and references implementation in `do.py`, while the static analyzer detected file read capability but the manifest does not declare any tool scope such as `permissions` or `allowed-tools`. This creates an authorization and transparency gap: consumers and hosting platforms cannot easily assess or constrain what the skill may access, increasing the risk of unintended local file exposure if the implementation reads beyond its expected data files.
