Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill documentation instructs execution of local shell scripts that read environment data and perform file writes into a user Obsidian vault, but it does not declare any permissions for those capabilities. This creates a trust and review gap: users or enforcement systems may assume the skill is low-privilege when it can modify local files and access environment-derived paths, increasing the chance of unintended data modification or abuse if the scripts are changed or invoked with unsafe inputs.
