Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill documentation indicates file read/write capabilities and a packaged executable path, but it does not declare permissions accordingly. This creates a governance gap where reviewers or runtime controls may underestimate what the skill can access, increasing the chance of unintended file access or unsafe deployment assumptions.
