Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill instructs the agent to locate a ledger CSV and append entries by invoking a Python script, which is file-write behavior, yet it declares no corresponding permission or capability boundary. This creates a transparency and least-privilege problem: users and the platform may not realize the skill can modify local files, increasing the chance of unintended ledger changes.
