Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 81% confidence
- Finding
- The skill documentation instructs the agent to read input files and write reports/JSON outputs, but it does not declare corresponding permissions. This creates a mismatch between the stated capability surface and the permission model, which can lead to unintended file access or writes if the runtime relies on explicit declarations for policy enforcement or user awareness.
