Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill exposes file read/write capabilities through documented scripts but does not declare those permissions in its manifest, which breaks least-privilege and prevents users or orchestration layers from understanding the actual trust boundary. Hidden or undeclared filesystem access is dangerous because it can be used to persist data, modify local state, or read sensitive files under the guise of a simple extractor.
