Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 82% confidence
- Finding
- The skill appears to perform file-based transformations and the static analysis detected file read/write capabilities, but the manifest does not declare any explicit tool scope such as permissions or allowed-tools. This creates an overbroad trust boundary: a host may permit filesystem access implicitly or users may be unable to review the skill's required capabilities, increasing the risk of unintended file access or overwrite if the implementation is later added or changed.
