Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 82% confidence
- Finding
- The skill is invocable and references implementation in `run.py` that reads `data.json`, but the manifest does not declare any tool scope such as `permissions` or `allowed-tools`. That creates an authorization/expectation gap: reviewers and runtime policy may not clearly understand that file-read capability is required, which can lead to overbroad defaults or unsafe execution assumptions.
