Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill explicitly instructs the agent to load references, templates, and a verification script, which implies file-read capability without a corresponding declared permission boundary. That creates a mismatch between what the skill can cause the agent to access and what reviewers or policy systems may expect, increasing the risk of unintended local file exposure or use of sensitive repository content.
