Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 82% confidence
- Finding
- The skill exposes operational guidance for MCP interaction and code-generation workflows, and the analyzer detected file-write and MCP-capable behavior without any explicit permission declaration. In an agent skill system, undeclared capabilities weaken policy enforcement and user awareness, which can allow the skill to create/modify files or interact with MCP tools in ways the operator did not explicitly approve.
