Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill advertises no explicit permissions while its documented workflow and optional script imply file reads, file writes, and shell/script execution. That mismatch is dangerous because it prevents accurate policy enforcement and user review, allowing broader capabilities than expected in a content-editing skill.
