Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill declares tools `read, exec` and documents persistent writes to local JSON files, yet there is no explicit permissions model or narrowing of allowed file paths/operations. This creates a real risk of unauthorized customer-data read/write behavior, especially because the skill processes tenant and customer identifiers that could influence file access decisions.
