Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill instructs the agent to read environment variables and to persistently read/write local data, but it does not declare these capabilities or warn users up front. This creates a trust and consent gap: users may invoke reporting features without realizing team/member/work-log data will be stored on disk and subscription state will be read from the environment.
