Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill instructs the agent to run a local script that generates .tex files under the target project, which is a file-write capability, but it does not declare any corresponding permissions. Undeclared write behavior is risky because users and policy layers cannot accurately constrain or review filesystem modifications, and a compromised or buggy script could overwrite project files unexpectedly.
