Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill documents scripts that read from user-supplied file paths and write local data, but it does not declare any permissions for those capabilities. This creates a trust and policy gap: the platform and users are not clearly informed that the skill can access local files, increasing the risk of unintended file exposure or modification if the scripts are invoked with sensitive paths.
