Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill documentation describes file-reading and file-writing behavior via raster inputs, GeoJSON inputs, and output artifacts, but it does not declare permissions for those capabilities. Undeclared filesystem access is dangerous because users and orchestration systems may grant or assume a lower privilege profile than the skill actually requires, reducing transparency and weakening security controls around local data access.
