Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 83% confidence
- Finding
- The skill advertises operational behavior that reads and writes local files via an auxiliary script, but it declares no permissions or user-consent boundary for those capabilities. That creates an authorization gap: users and the platform may treat the skill as text-only while it can materially modify local workspace contents.
