Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill description indicates it analyzes disk usage for arbitrary paths, which necessarily involves reading the filesystem, but the skill declares no corresponding permissions. That creates a real least-privilege and transparency issue: users and enforcement systems are not informed that the skill can access local files and directory metadata, increasing the chance of unintended exposure of sensitive paths.
