Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 81% confidence
- Finding
- The skill directs persistent reads and writes under ~/.uxr-observer/ even though no explicit permissions are declared. That mismatch weakens informed consent and platform enforcement because a user or host may not realize the skill will continuously store behavioral data locally.
