Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill instructs the agent to read local reference files such as `references/products.json`, `references/insurance-knowledge.md`, and `references/compliance.md`, but no corresponding permission declaration is present. This creates a capability/permission mismatch: in permissive runtimes the skill may access local files without explicit review, while in stricter runtimes it may fail unpredictably, undermining security review and least-privilege controls.
