Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill demonstrates file read/write behavior throughout the guide but does not declare corresponding permissions. In an agent environment, undeclared file capabilities reduce transparency and can cause the skill to be invoked with broader filesystem effects than reviewers or runtime policy expect.
