Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill documentation advertises scripts that read from local inputs and write outputs to user-specified files, but the skill declares no corresponding permissions. That mismatch is a real security issue because agents or users may invoke file-capable workflows without an explicit trust boundary, increasing the chance of unintended file access or overwriting files in the local environment.
