Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill instructs the agent to read a user-supplied file path via `python scripts/text_stats.py <文件路径>`, which implies file-read capability, but no corresponding permission is declared. Undeclared file access weakens security boundaries and can lead to unintended access to sensitive local files if the skill is invoked on arbitrary paths.
