Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill instructs the agent to read multiple workspace files and optionally generate a report via a script with an output path, which implies file read and file write capabilities, but no permissions are explicitly declared. This creates a trust and enforcement gap: operators may assume the skill is read-only from metadata while it can access and write files, increasing the risk of unintended data exposure or unauthorized modification if invoked in sensitive workspaces.
