Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill instructs the operator to create workspaces, write `.env` files, and perform backup/rollback operations, which clearly imply file read/write behavior, yet it declares no permissions. That mismatch can mislead users and enforcement systems about the skill's capabilities, reducing transparency and weakening least-privilege controls around filesystem access.
