Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill declares 'no external dependencies' and documents scripts that read and write local files under ./inspection_data/, but it does not declare any permissions or capability boundaries. Undeclared file read/write is risky because an agent or platform may execute the skill with broader filesystem access than users expect, enabling unintended access, overwrite, or persistence beyond the intended data directory.
