Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 80% confidence
- Finding
- The skill invokes a local Python script and static analysis indicates file read/write capabilities, but the skill declares no permissions. Undeclared filesystem access is dangerous because it can surprise operators, bypass expected trust boundaries, and allow persistent modification of local files if the surrounding agent executes the referenced tooling.
