Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 80% confidence
- Finding
- The skill advertises file read/write behavior but does not declare corresponding permissions, which weakens transparency and policy enforcement around filesystem access. In an agent environment, undeclared file capabilities can lead to unintended access to local templates or output paths and make it harder for users and reviewers to understand the skill's real privileges.
