Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill reads environment variables, reads arbitrary input materials, and writes multiple output artifacts, but no permissions are explicitly declared. That creates a trust-boundary problem: operators and users are not warned that the skill can access local files and env-backed data, increasing the chance of unintended data exposure or unsafe deployment assumptions.
