Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 82% confidence
- Finding
- The skill advertises executable commands that read workspace files, inspect configuration, and write snapshot outputs, but it does not declare corresponding permissions. This creates a trust and containment gap: a host may treat the skill as low-privilege based on metadata while the documented behavior clearly requires file read, file write, and likely environment access, increasing the chance of unauthorized data exposure or unintended modification when invoked.
