Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill documentation instructs users to run a local Python script that reads meeting notes, writes JSON/Markdown/email outputs, and accepts prior JSON files, which clearly implies file_read, file_write, and shell execution capabilities. Because these capabilities are present but no permissions are declared, the skill creates a transparency and policy gap: operators may invoke it with broader access than expected, increasing the chance of unintended exposure or modification of sensitive meeting data.
