Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill advertises scanning arbitrary files, directories, and repositories and saving reports, which implies file read and file write capabilities, but it does not declare any permissions or constraints. This creates a transparency and least-privilege problem: an agent may invoke filesystem access broader than users or reviewers expect, increasing the risk of over-collection of sensitive data and unintended writes.
