Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill clearly instructs reading and modifying a user-specified markdown file, yet no permissions are declared. Undeclared file read/write capability is dangerous because users and orchestration systems may not realize the skill can alter local data, reducing transparency and consent around data access and modification.
