Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill explicitly states it can deploy generated XML to /boot/config/plugins/dockerMan/templates-user/my-<name>.xml, which is a file-write capability, but no declared permission is present. Undeclared write capability is dangerous because it can modify host configuration artifacts and create persistence or deploy malicious container templates without the platform enforcing the proper trust boundary.
