Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill clearly instructs reading local files under ~/.codex, which is a file-read capability handling potentially sensitive data, yet it declares no explicit permissions or warning boundary. That mismatch can mislead users and downstream systems about the skill's access scope, increasing the chance of unintended disclosure of session metadata and message content.
