Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill instructs the agent to read reference files, generate an input JSON in the workspace, and run a local script that writes a report, but it does not declare corresponding permissions. This creates a capability/permission mismatch that can lead to unauthorized file access or writes if the runtime enforces permissions separately from the skill text, and it weakens auditability of what the skill is allowed to touch.
