Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill documentation describes filesystem and environment-dependent operations such as persistent memory files, summaries, and vector-store usage, but it does not declare corresponding permissions. In an agent ecosystem, missing permission declarations can bypass user/operator expectations and reduce enforcement or review of file and environment access, especially for a component designed to persist conversation data.
