Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill clearly performs file/database write operations against a local Zotero SQLite file, but the manifest declares no required permissions or equivalent guardrails. That mismatch can cause the agent platform to under-classify the skill's risk and invoke a database-modifying capability without explicit user/admin acknowledgement.
