Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill appears to perform file read/write operations despite not declaring any permissions, which breaks transparency and prevents users or hosting systems from accurately assessing what the skill can access. Undeclared filesystem capabilities can be abused to create, modify, or inspect local files in ways the user did not authorize or expect.
