Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill advertises local CSV-based analysis but does not declare permissions even though its documented usage includes reading input files and writing JSON output. Undeclared file capabilities reduce transparency and can cause the agent platform or user to authorize behavior they did not explicitly review, which is a security and trust boundary issue.
