Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 85% confidence
- Finding
- The skill advertises file-reading and file-writing behavior through the referenced redline checker, but no explicit permissions are declared. That creates a transparency and authorization gap: a caller may invoke a writing workflow without realizing the skill can scan local .md/.txt files and potentially modify them in place. In a content-production context this is not inherently malicious, but undeclared write capability can still lead to unintended data modification or over-broad file access.
