Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 82% confidence
- Finding
- The skill advertises and instructs use of scripts that read inputs and write outputs, but it does not declare permissions or clearly surface those capabilities. In an agent setting, undeclared file access can lead to users or orchestrators invoking the skill without understanding that local files may be read or overwritten.
