Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill documentation clearly instructs the agent to run a local Python script that reads and writes files, but the skill does not declare those capabilities as permissions. This creates a transparency and policy-enforcement gap: an agent or reviewer may underestimate the skill's ability to modify user data in the Obsidian vault, increasing the risk of unintended file access or writes.
