Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill explicitly instructs the agent to read `references/style-guide.md`, optionally read multiple files under `references/articles/`, and use `references/generate_report.py` to write a single-file HTML report, which implies file-read and file-write behavior without any declared permissions. Undeclared file capabilities create a trust and containment gap: the host or reviewer cannot accurately assess what resources the skill needs, and broad file access patterns can be abused or misconfigured to read unintended files or write artifacts in unsafe locations.
