Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill clearly instructs users to read canonical rule files and generate multiple output files, which implies filesystem read/write behavior, but it does not declare those capabilities or permissions explicitly. This weakens transparency and reviewability, making it easier for a user or orchestrator to invoke a repository-wide write operation without understanding the scope of file modifications.
