Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill explicitly demonstrates saving an output .ghx file and describes file-writing behavior, but no declared permissions or safety constraints are visible in the skill document. Undeclared write capability is risky because an invoking agent or user may not be aware that the skill can create or overwrite local files, which can lead to unintended filesystem changes.
