Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill explicitly reads uploaded experiment documents and generates a multi-file project on disk, which are file read/write capabilities, yet no permissions are declared. This creates a trust and policy gap: users and the platform may not realize the skill can access inputs and persist generated artifacts, increasing the chance of unintended file access or unsafe writes.
