Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill advertises itself as 'pure local' and 'read-only CSV', but its documented usage includes writing output files via --output and the metadata does not declare permissions for file read/write. This creates a trust and policy gap: a host may expose file access implicitly without users understanding the scope, increasing risk of unintended file access or overwrite.
