Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill instructs automatic export of analysis output to a markdown file, which is a file-write capability not declared in the manifest. Undeclared write behavior breaks the principle of least privilege and can surprise users by persisting potentially sensitive prompts, reasoning, or recommendations to local storage without explicit consent.
