Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill advertises itself as invocable but does not declare any explicit tool scope or permissions, while static analysis detected file-read capability in the implementation. This creates a trust and containment gap: users and reviewers cannot tell from the manifest what local file access the skill may perform, which can enable unintended data exposure if the runtime grants broader access than expected.
