Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill documentation describes persistent local state in `data/pipeline_state.json` and exposes file-backed workflow behavior, but no corresponding permissions are declared. This creates a capability/permission mismatch that can cause silent overreach, unsafe deployment assumptions, or unauthorized read/write of local data if the runtime infers or allows these operations implicitly.
