Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill explicitly instructs reading user-supplied local files in multiple formats and invoking other skills/libraries to extract content, but it declares no permissions or safety boundaries for file access. This creates an authorization and transparency gap: an agent may read local files without clear user consent semantics or sandbox constraints, which can expose sensitive data if file selection or path handling is broader than intended.
