Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill performs file reads, file writes, and uses environment-provided paths, but it does not declare explicit permissions or constraints for those capabilities. Because it is user-invocable and operates on configurable filesystem locations, this creates an authorization gap: the runtime and reviewers cannot reliably enforce or audit what files the skill may access or modify, increasing the risk of unintended or unsafe file operations if configuration is wrong or manipulated.
