Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill documentation indicates capabilities that read local files (for redlists and vendored code paths) and write per-message audit logs, but no permissions are declared. That mismatch can lead integrators to grant or assume broader filesystem behavior than is transparently documented, weakening review and sandboxing controls for a component intended to sit in a sensitive outbound approval path.
