Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill is invocable and references code in `do.py` that can read files, but the manifest does not declare any `permissions` or `allowed-tools` scope. That creates an authorization ambiguity: the runtime may grant broader file-read capability than a reviewer or caller expects, which increases the risk of unintended local file access if the implementation changes or is misused.
