Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill advertises file read/write behavior (template loading and PPTX output generation) but does not declare any permissions, which creates a mismatch between the documented capability surface and the security model. In an agent environment, undeclared filesystem access can bypass user expectations and platform controls, and this is more sensitive here because the skill accepts filenames as inputs and writes output files to disk.
