Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill instructs reading two user-supplied files and writing an output file, but it does not declare any permissions despite clearly requiring file read and file write capabilities. In an agent environment, this mismatch can bypass least-privilege controls or prevent reviewers from accurately understanding the skill's access scope, increasing the risk of unintended file access or overwrite if invoked with sensitive paths.
