Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill clearly instructs the agent to read local markdown and image files and to write manifests, JSON summaries, markdown output, and a PPTX, but it does not declare corresponding permissions. This creates a policy/visibility gap: users and enforcement layers may not realize the skill can access arbitrary local paths supplied in arguments, increasing the chance of unintended data exposure or file modification.
