Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill instructs the agent to read local reference files and a normalization script (`references/ai-services-template.md`, `references/playbook.md`, `scripts/batch_csv_to_brief.py <file>`) while the metadata does not declare permissions. This creates an undeclared file-read capability and can lead to unexpected access to local files or user-provided paths, especially when a user supplies a CSV filename.
