Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 83% confidence
- Finding
- The skill advertises scaffold and module creation behavior that implies filesystem access, yet it does not declare permissions for file_read and file_write. Undeclared capabilities weaken user consent and platform enforcement because the skill can modify project files without the permission surface being made explicit.
