Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill instructs the agent to generate an SVG and explicitly write it to disk via an output path, but the skill metadata does not declare any corresponding file-write permission. This creates a capability/permission mismatch: an agent may perform filesystem writes that are not surfaced to policy or users, increasing the risk of unintended overwrites or writing to sensitive/user-visible locations.
