Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill documentation advertises shell execution plus file read/write behavior, but no permissions are declared. That creates a trust and containment gap: a caller or review system may assume the skill is low-risk while it can persist data and operate on the filesystem, including an arbitrary workspace path. In this context, persistent task storage and alternate workspace access make the undeclared capabilities more concerning, because they enable modification or inspection of files outside the skill’s own directory.
