Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill explicitly instructs the agent to read and write files under `life/areas/**` and to invoke a bundled Python script that performs those updates, but the skill declares no permissions. This creates a capability/permission mismatch that can bypass expected review and containment controls, making unauthorized filesystem modification easier if the skill is invoked in a broader environment.
