Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill metadata declares no permissions, yet the analyzed behavior indicates file read and file write capabilities. Undeclared filesystem access is risky because it prevents informed consent and review, and in a memory-oriented skill it could expose or modify local data outside the user’s expectations.
