Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill advertises file output functionality via the optional --output parameter but does not declare corresponding permissions. Undeclared write capability can bypass user and platform expectations, allowing reports or generated content to be written to arbitrary local paths if the underlying tool honors user-supplied paths.
