Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill explicitly instructs the agent to traverse `skills/`, read existing `SKILL.md` files, create directories, write new skill packages, and run validation scripts, which are file read/write capabilities. Because no declared permissions are present, the effective authority is broader than what a permission model or reviewer can verify, increasing the risk of unintended workspace modification or data exposure if the skill is triggered in the wrong context.
