Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill documentation describes reading input transcripts and optionally writing JSON output, but it declares no permissions despite those code capabilities being present. This creates a permission-transparency gap: operators may approve or run the skill without understanding it can access local files, which increases risk if the implementation is later modified, misused, or pointed at sensitive paths.
