Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill instructs the agent to read local files under references/ and inspect canon.json, but it declares no permissions. Hidden file-read behavior creates a trust boundary issue: users may believe this is only a persona/helper prompt when it actually accesses workspace content. In an agent environment, undeclared reads can expose local data or normalize broader capability use without user awareness.
