Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill advertises 'pure local' operation and only reading CSV input, but the usage examples include writing output to analysis.json and the analyzer detected both file_read and file_write capabilities without any declared permissions. Undeclared file access weakens trust boundaries and can let a host invoke the skill with broader filesystem effects than users or reviewers expect.
