Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill instructs the agent to read local conversation history via a Python script, but it does not declare corresponding permissions or clearly surface that capability in a machine-readable way. Undeclared file-read behavior is dangerous because it weakens user consent and policy enforcement around access to potentially sensitive local transcripts.
