Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill documentation advertises executable paths and file-based JSON input/output, which implies file read/write capability without any declared permissions or trust boundary. This is dangerous because agents or reviewers may treat the skill as lower risk than it is, leading to unintended access to local files and output locations.
