Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 78% confidence
- Finding
- The skill advertises no declared permissions while static analysis detected file read/write capabilities, creating a transparency and least-privilege problem. Even if the file access is only intended for local progress tracking, undeclared filesystem access increases the attack surface and can enable unintended access to user data or overwriting of local files if the runtime grants those capabilities.
