Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill instructs the agent to use local resources such as `references/templates.md`, `scripts/task_extractor.py`, and `scripts/meeting_summary.py`, which implies file read capability and likely file output generation, yet no permissions are declared. This creates a trust and containment problem: a caller may invoke what appears to be a text-only summarization skill, while the agent is actually encouraged to access bundled files and generate artifacts, increasing the attack surface and making unintended file access harder to audit.
