Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill instructs use of environment variables and local scripts that read and write files, but no permissions are declared. This creates an authorization gap where an agent may access the workspace or modify/archive CSVs without an explicit permission boundary, increasing the risk of unintended file exposure or tampering.
