Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill exposes file read/write capabilities through its documented patch workflow but does not declare permissions, which can bypass reviewer and runtime expectations about what the skill is allowed to do. In an agent environment, hidden filesystem modification capability increases the risk of unauthorized local file changes, especially when the skill can patch arbitrary target paths.
