Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill advertises and instructs use of scripts that read arbitrary project paths, write analysis reports, and may interact with external references, yet no permissions are declared. Missing permission declarations undermine the platform trust model and can cause users or orchestrators to invoke capabilities without informed consent or appropriate sandboxing.
