Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill explicitly states it will read local configuration from ~/.zlbx/config.json and write reports to ~/zlbx-company-intel-files/, but only declares an environment-variable requirement and no corresponding file permissions. This creates a permission-model bypass risk: operators and users cannot accurately understand or constrain what local resources the skill may access, increasing the chance of unintended file exposure or modification.
