Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill instructs the agent to invoke local scripts that read input records and write structured outputs to files (for example via stdin, input paths, /tmp outputs, batch directories, and generated JSON bundles), but the metadata declares no permissions. That mismatch is a real security issue because it obscures the skill's filesystem access requirements, weakening policy enforcement and informed approval, especially given the highly sensitive medical data being processed.
