Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill declares tools `python` and `file` and explicitly instructs running Python scripts that read memory inputs and write snapshots/reports, yet no explicit permissions model is declared. This creates a capability/authorization mismatch: an agent or platform may expose file read/write and shell-like execution without the user being clearly informed of the scope, increasing the risk of overbroad access to sensitive memory files.
