Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill describes file-modifying behavior via the migration script, but no explicit permissions declaration is present. This creates a capability/permission mismatch that can lead an agent platform or user to underestimate the skill's ability to write and move files, increasing the risk of unintended destructive changes if the skill is invoked.
