Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill clearly performs local file write operations by moving, copying, renaming, and potentially generating reports, yet no permissions are declared. Undeclared write capability weakens user consent and platform enforcement because a caller may not realize the skill can modify filesystem state before invocation.
