Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill advertises local JSON storage in `~/.portfolio/` and examples imply persistent file creation/modification, yet no permissions are declared. This creates a capability/consent mismatch: an agent or user may invoke a seemingly low-privilege finance skill without being warned that it writes to disk and may access environment-derived paths such as the home directory.
