Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 82% confidence
- Finding
- The skill appears to have effective file read/write capabilities despite not declaring any permissions, which creates a transparency and policy-enforcement gap. In an agent environment, undeclared I/O access can lead to unintended reading of sensitive files or writing migration artifacts without explicit user awareness or approval.
