Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 83% confidence
- Finding
- The skill is marked invocable and references implementation in `do.py`, while the manifest does not declare any `permissions` or `allowed-tools` despite detected file-read capability. This creates an authorization/visibility gap: reviewers and runtime policy may not have an explicit declaration of what the skill is allowed to access, increasing the risk of unintended local file access if the code reads beyond the intended bundled data files.
