Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill declares no permissions, yet its documented behavior clearly includes reading files, writing semantic state under ~/.lucid-skill/, and consuming environment variables such as LUCID_DATA_DIR and embedding settings. This mismatch can bypass least-privilege review and cause users or orchestrators to grant or allow broader filesystem and environment access than is transparently declared, which is especially sensitive for a tool that connects to local files and databases.
