Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill documentation exposes executable commands that invoke a local Python script and also describes design-system generation that can write files, yet no permissions are declared. This creates a trust and containment gap: an agent or user may run filesystem-capable behavior without an explicit permission contract, increasing the risk of unintended local file reads or writes.
