Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill references a local script and additional repository files, implying file read/write capability, but it does not declare any explicit tool scope or permission boundaries. In an agent environment, this can lead to over-broad tool access being inferred or granted implicitly, increasing the chance of unintended file access or modification beyond the skill's intended purpose.
