Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 83% confidence
- Finding
- The skill text instructs reading input, handling large inputs in chunks, and effectively implies writing converted output, yet it declares no permissions. Undeclared file read/write capability creates a trust gap: an agent or reviewer may authorize the skill under false assumptions, enabling unintended access to local data or persistence of transformed content.
