Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill instructs the agent to read and write local files and persist data under the user's home directory, but it does not declare those permissions. This creates a transparency and consent problem: users or the platform may not realize the skill can modify local state, which increases risk if the skill is triggered unexpectedly or abused.
