Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill instructs the agent to invoke a local script that writes files to an output directory, which is a code-capable behavior despite no declared permissions. This creates an accountability and sandboxing gap: users and reviewers may treat the skill as purely editorial while it can perform filesystem actions, increasing the chance of unintended file creation or misuse in broader agent environments.
