Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill advertises file-writing behavior and directs execution of a Python script that copies sensitive configuration data, but it does not declare corresponding permissions. This creates a transparency and governance gap: users and security controls may not realize the skill can write sensitive material to disk, increasing the risk of unauthorized persistence or misuse.
