Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill advertises safety analysis functionality while demonstrating file read/write capabilities without any declared permissions model or explicit scope boundaries. Even though the text claims it will not access sensitive information, undeclared filesystem access increases the attack surface and weakens user consent, especially for a skill positioned as an ethics/safety utility that may be trusted with broad deployment.
