Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill advertises executable processing steps and file transformations that imply read/write access, but it does not explicitly declare permissions or clearly bound filesystem scope. This creates an authorization and transparency gap: an agent or user may run code that reads input files and writes reports without clear consent boundaries, increasing the risk of unintended file access or overwrite.
