Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 79% confidence
- Finding
- The skill is documented as a data-fetching tool, but the available commands include operations that can write or alter state, such as creating, renaming, deleting, and clearing custom sectors, and downloading files. When state-changing or file-writing capabilities exist without an explicit permissions declaration, users and orchestration systems may underestimate the tool's authority and invoke it in unsafe contexts.
