Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill instructs the agent to read reference files and run scripts that generate output files, which implies file read/write capability, but no permissions are explicitly declared. This can lead to an agent being granted or assuming broader filesystem access than reviewers expect, increasing the risk of unintended data exposure or modification on the local machine.
