Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill instructs the agent to read local files such as `references/copywriting-frameworks.md`, `assets/sequence-template.md`, and to run `scripts/deliverability_check.py`, but no permissions are declared. That creates an undeclared capability boundary: users and platform policy may assume a purely textual skill while it actually depends on file access and script execution paths, which can expand attack surface and enable unintended data access or tool use.
