Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill clearly instructs the agent to create directories, generate templates, copy scripts, and upgrade existing projects, which requires filesystem read/write behavior. Having those capabilities implied in the content but not explicitly declared weakens permission transparency and can cause an agent runtime to perform broader file operations than a user expects.
