Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill instructs users to run a local Python script that scans workspace files and can write reports, but the manifest does not declare any explicit tool scope or permissions. This creates a capability/expectation mismatch: an agent or reviewer cannot easily tell from the skill metadata that filesystem read/write access is required, which can lead to overbroad execution in sensitive workspaces.
