Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill advertises file read/write behavior through its documented commands and outputs, but no permissions are declared. That creates a trust and sandboxing problem: users or hosting systems may approve the skill under the assumption it is non-privileged, while it can still read input files and write generated artifacts such as JSON and HTML to disk.
