Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill instructs use of an environment variable (`TODO_LIST_DB_PATH`) to alter file-write behavior, but it does not declare any explicit tool scope or permissions boundary. That can let the agent operate on an unexpected filesystem target if the runtime honors attacker-influenced environment values, increasing the risk of unintended reads/writes or persistence outside the intended database location.
