Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill documentation indicates the script can write output files (`--output`, generated artifacts) while no explicit permissions are declared. That mismatch is a real security concern because an agent or reviewer may assume the skill is read-only when it can modify the filesystem, increasing the chance of unintended overwrites or writes outside the intended workspace if the implementation is weak.
