Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill invokes a local script against a user-supplied JSON file (`subs.json`), which implies file-read capability even though no permissions are declared. Undeclared capabilities are dangerous because they weaken consent and review boundaries: an agent or user may not realize the skill accesses local files, and future implementations could broaden that access beyond the intended subscription file.
