Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill clearly instructs agents to inspect workspace trees, scaffold directories, append indexes, and write reference stubs, which are file read/write capabilities. However, the skill metadata does not declare any permissions, so an agent or platform may execute filesystem actions without explicit authorization boundaries or user-visible consent controls. In a filesystem-oriented skill, undocumented write access is especially risky because it can modify user workspaces broadly even if the stated intent is additive only.
