Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill instructs reading local files and generating output artifacts, but the manifest does not declare any permissions. That creates a transparency and policy-enforcement gap: users and the platform may not realize the skill can access filesystem paths, logs, templates, and dumped framebuffer binaries, increasing the chance of unintended data exposure or unauthorized file access.
