Context-Inappropriate Capability
Medium
- Confidence
- 92% confidence
- Finding
- The documented `file_operations` tool exposes arbitrary read, write, list, and delete-style file system capabilities via a generic path argument, with no path restrictions, sandboxing, or authorization checks. In an MCP context, this is dangerous because a connected model or user could be induced to access or modify sensitive local files far beyond mere server scaffolding, enabling data theft, destructive changes, or persistence.
