Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill instructs the agent to read local repository files such as `references/copywriting-frameworks.md`, `assets/sequence-template.md`, and to run `scripts/deliverability_check.py`, but it declares no `permissions` or `allowed-tools` scope. That mismatch can lead to implicit or overly broad file/tool access at runtime, increasing the chance of unauthorized file reads or execution in environments that auto-grant capabilities.
