Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill documents file-writing behavior (`--output`, output JSON file path) but does not declare corresponding permissions or constraints, which creates a transparency and governance gap around filesystem access. In a tool that may handle personal, academic, or manuscript content, undeclared write capability increases the risk of users or hosting platforms underestimating where sensitive data may be stored.
