Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill clearly instructs reading a user-supplied CSV and writing multiple local output files, but it does not declare permissions or otherwise signal those file access capabilities. That reduces transparency and makes it harder for a host or user to assess data exposure risk before execution, especially because review data may contain personal or commercially sensitive content.
