Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill advertises no declared permissions, yet the documentation clearly indicates file read/write behavior through PDF ingestion and watchlist persistence. This creates an undeclared capability gap: users and the platform cannot accurately reason about what local data the skill may access or modify, increasing the risk of unintended file access or silent data persistence.
