Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill declares environment-variable use and persistent file reads/writes, but does not declare corresponding permissions. That mismatch weakens policy enforcement and user visibility, because a caller may treat the skill as low-privilege while it can still access workspace paths and write medication history data. In this context, the written data is sensitive health-related information, which increases the consequence of undeclared file access.
