Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill documentation describes persistent reads and writes to local JSON files, but no permissions are declared. That creates a trust and containment gap: a host may load the skill expecting a harmless sticker feature while it can modify local state, and in some runtimes undeclared file access weakens policy enforcement and review. The risk is amplified because the writes are automatic on first use and during cooldown tracking, not just explicit admin actions.
