Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill instructs reading and writing `memory/weibo-state.json` but does not declare any permissions or prominently disclose that persistent local storage is used. Undeclared file I/O weakens the trust boundary for a skill that also performs live posting, because users and reviewers may not realize posting history and content are being retained on disk.
