Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill clearly instructs users to read and rename files, create backups, and write a manifest, which implies file read/write capabilities despite no declared permissions. This mismatch is dangerous because it hides the skill’s true access requirements from any permission-review or policy-enforcement layer, reducing transparency and making unintended file modification harder to audit or constrain.
