Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill documentation describes reading input files and writing output CSV/JSON files, but it does not declare any explicit tool scope such as permissions or allowed-tools. This creates an authorization gap: an agent may be allowed to perform file reads and writes without clear restriction, increasing the chance of unintended access to sensitive files or overwriting user data when the skill is invoked on arbitrary paths.
