Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill clearly performs filesystem reads on user-supplied PDF, HTML, Markdown, CSS, and output paths, but it does not declare any permissions. This creates a mismatch between documented capabilities and the security model, which can lead to unauthorized or overly broad file access if the runtime relies on declared permissions for enforcement or review.
