Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill documents reading a local token file but does not declare corresponding permissions, creating a mismatch between advertised and actual capabilities. In an agent setting, undeclared file-read behavior is security-relevant because it can expose sensitive local data and bypass user expectations about what the skill may access.
