Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill documentation clearly instructs users to run a Python script that creates, updates, and indexes files under docs/adr, which implies file read and file write capabilities, yet no permissions are declared. This creates a trust and review gap: an agent or user may invoke a skill with filesystem effects without explicit authorization boundaries or disclosure of what paths can be modified.
