Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill instructs the agent to read and write local files (`content_<日期>.py`, `build_<日期>.py`, `briefing.html`, `memory.md`) without declaring corresponding permissions. Undeclared filesystem access weakens trust boundaries and can lead to unintended reads or overwrites if the runtime grants broader file access than users expect.
