Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill clearly instructs reading source project files and writing multiple output artifacts, but it declares no permissions or trust boundary information. This creates a capability-transparency problem: users and the hosting platform may not realize the skill can access local files and generate archives, increasing the risk of unintended file access or overwrite during execution.
