Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill exposes file read/write capability through script usage and `--output` / `@file_path` patterns, but it does not declare any explicit tool scope or permissions boundary. In an agent environment, undeclared capabilities increase the chance of the skill being invoked with broader filesystem access than intended, making accidental data exposure or overwriting of local files more likely.
