Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 85% confidence
- Finding
- The skill documentation describes capabilities that read and modify session files, create backups, restore data, and delete JSONL session files, yet no explicit permissions are declared. This creates a trust and review gap: operators may invoke a skill with filesystem side effects without clear disclosure of its file access scope, making accidental misuse or overbroad implementation more likely.
