Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill clearly instructs the agent to read local files such as `.editorconfig` and source trees (`src/`), but no permissions are declared to communicate that capability. This creates a transparency and policy-enforcement gap: an operator may treat the skill as lower risk than it is, while the skill can still access repository contents and expose file-derived data in output.
