Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill instructs the agent to read local reference files and run Python scripts against a project directory, which implies filesystem access capabilities, yet no permissions are explicitly declared. This mismatch is dangerous because it can cause the skill to operate with undeclared file read/write behavior, reducing transparency and weakening policy enforcement or user trust around what the skill is allowed to access.
