Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill explicitly directs the agent to use local scripts and reference files, which implies file-read/code-adjacent capability, but it declares no permissions or boundaries. This creates a trust and enforcement gap: an orchestrator may allow the skill to access repository files or corpora without clear user-visible authorization, increasing the chance of unintended data exposure during analysis.
