Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill clearly instructs the user/agent to run local Python code that reads arbitrary iWork files and can write Markdown output next to the source or to an explicit path, but the skill metadata does not declare those file access capabilities. This is a real security-relevant issue because undeclared read/write behavior reduces transparency and can bypass policy controls or user expectations about what the skill is allowed to do.
