Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill instructs the agent to run a scaffold script that writes files to a user-specified output directory, but the metadata declares no permissions. This creates a capability mismatch: an execution environment or reviewer may assume the skill is read-only when it can actually modify the filesystem, increasing the risk of unexpected file creation or overwriting during use.
