Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 81% confidence
- Finding
- The skill explicitly instructs use of local scripts and file processing workflows (`scripts/doc_reader.py`, `scripts/validate_dual_view.py`) but does not declare permissions for file read/write. Hidden or undeclared filesystem access weakens the trust boundary: operators may approve the skill believing it is documentation-only, while it can in practice access or modify local artifacts involved in knowledge-base generation.
