Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill documentation describes file read/write behavior but does not declare corresponding permissions or constraints, which creates a transparency and policy-enforcement gap. In a clinical context, undocumented filesystem access increases the risk of unauthorized handling of sensitive EHR data, especially if path validation or workspace restrictions are not actually enforced in code.
