Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill instructs the agent to read user-supplied log files and write parsed/analysis output files, but it does not explicitly declare those capabilities or constrain where reads and writes may occur. In an agent environment, undeclared file access increases the chance of overbroad filesystem access, accidental processing of unrelated local files, or writing sensitive derived data to unsafe locations.
