Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill documentation describes reading from local iCloud/Apple Health export paths and writing health data into local JSON files, but it does not declare corresponding permissions. Undeclared file access is a security and trust problem because agents or users cannot accurately assess what local data the skill can read and persist, especially when the data is highly sensitive health information.
