Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill documents file read/write behavior by storing records in a local JSON file, but it does not declare any permissions for those capabilities. Undeclared filesystem access weakens transparency and consent, making it harder for users or platforms to assess what the skill can modify or persist.
