Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill instructs the agent to read templates and generate files, which implies file read/write capabilities, but it does not declare those permissions. Undeclared capabilities weaken review and user consent because the skill can access or modify local content without an explicit permission model, making the behavior less transparent and easier to misuse.
