Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill clearly describes local file read/write capabilities and persistent storage behavior, but it does not declare any permissions or present guardrails for those capabilities. Undeclared file access is dangerous because it can surprise the host environment, bypass policy expectations, and enable silent persistence of user data beyond what users or operators intended.
