Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill explicitly describes generating an H5 page via generate_html.py, which implies file creation/write behavior, yet no permissions are declared. Undeclared file-write capability weakens transparency and reviewability, making it easier for a skill to write unexpected files or overwrite local artifacts without clear operator awareness.
