Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill explicitly claims it will generate files, create directory structures, and package them into a zip archive, which implies file read/write behavior, yet no permissions are declared. This creates a capability/permission mismatch that can lead users or host systems to grant or execute filesystem actions without clear authorization boundaries, especially in a meta-skill that produces and packages artifacts automatically.
