Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill explicitly instructs the agent to read from `~/.zlbx/config.json` and write reports to `~/zlbx-company-intel-files/`, but it does not declare corresponding permissions. This creates a transparency and enforcement gap: users and platform controls may not realize the skill accesses local files, including a credential-bearing config file.
