Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill clearly describes writing a modified PPTX to an output path, which is a file-write capability, yet no declared permissions are present. Undeclared write access is risky because callers or policy layers may not realize the skill can create or overwrite files, reducing transparency and weakening permission enforcement.
