Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill clearly instructs the agent to create and save annotated output files, but it does not declare any permissions reflecting file-write capability. This mismatch can undermine permission gating, auditability, and user awareness, especially because the skill processes user-supplied files and writes modified copies to disk.
