Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 82% confidence
- Finding
- The skill documentation declares no permissions while the skill behavior implies filesystem access to scan migration directories and read SQL files. Undeclared file-read capability weakens transparency and policy enforcement, which can let a caller invoke broader data access than reviewers or operators expect.
