Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill instructs the agent to read, write, and enumerate local files in `./sms-rpg-saves/` without declaring corresponding permissions or constraining access through a documented capability model. Undeclared filesystem access is dangerous because it expands the skill's effective authority beyond what callers may expect, enabling unintended local data exposure or modification if the runtime honors these instructions.
