Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill documentation clearly describes file read and file write behavior, but no corresponding permissions are declared. This creates a transparency and policy-enforcement gap: users or orchestration systems may not realize the skill can access and create files, increasing the risk of unintended data exposure or unauthorized filesystem changes. In this context, the capability is expected for a file-splitting tool, which lowers suspicion of maliciousness, but the undeclared access is still a real security issue.
