Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 85% confidence
- Finding
- The skill describes filesystem scanning, report generation, and saving output, which implies file read and file write behavior, but it does not declare any explicit permissions or boundaries for those capabilities. This creates a least-privilege and transparency problem: an agent may be allowed to read broad directory contents and write reports without the user being clearly informed of scope or constraints.
