Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill explicitly instructs users to run a Python script that reads and writes SKILL.md files, and even supports batch modification of an entire skills directory, yet it declares no permissions or equivalent safety boundaries. This mismatch is risky because users and orchestration systems may treat the skill as low-risk while it can modify many local files, increasing the chance of unintended bulk changes or abuse if pointed at the wrong path.
