Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 79% confidence
- Finding
- The skill documentation describes multiple scripts that write files such as SDF, PDB, PNG, and arbitrary output paths via flags like --output and output_dir, but the skill declares no corresponding permissions. Undeclared file-write capability is a real security issue because downstream systems may execute the skill under a looser trust model than its actual behavior warrants, enabling unexpected filesystem modification or artifact creation.
