Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill instructs the agent to read numerous local reference files and even mentions checking local .txt/.md/.docx drafts, which implies file-read capability despite no declared permissions. Undeclared file access is dangerous because it expands the skill’s effective privilege surface and can lead to unintended access to local data outside the user’s expectations or policy controls.
