Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill instructs the agent to run a local parsing script on a user-supplied file path, which is a real file-read capability, but the skill declares no permissions. That mismatch weakens security review and user consent because the agent may access local files without an explicit capability declaration or path restrictions.
