Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill documentation instructs the agent to read configuration files and write result artifacts, yet the skill declares no permissions. This creates a trust and review gap: operators may enable a skill believing it is non-persistent and low-risk, while it actually performs filesystem access and stores user/model content.
