Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 80% confidence
- Finding
- The skill declares broad project scaffolding behavior but does not explicitly declare permissions despite describing capabilities to read files and use environment/global state. This weakens user consent and reviewability, because a user may invoke the skill without understanding that it will inspect local files and home-directory Claude state.
