Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill documents executable commands that read user-supplied medical records and write extracted data to files, but it does not declare corresponding permissions. That mismatch is a real security issue because it reduces transparency and policy enforcement around sensitive PHI/PII handling, especially given explicit use of stdin, input paths, output paths, temp files, and batch directory processing.
