Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill instructs the agent to run a local Python script and explicitly claims access to local data, which implies filesystem read capability, but the declared permissions only mention a binary requirement and omit an explicit file-read permission. This mismatch weakens security review and user consent because the skill can access local snapshot data without transparently declaring that capability.
