Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill documentation indicates file read/write capabilities via runtime state inspection and mutation (`cat memory/reply_state.json`, editing JSON, deleting the state file), but no declared permissions are present. Undeclared persistence and filesystem access weaken transparency and consent, and can lead to unexpected data retention or modification in environments that rely on declared permissions for policy enforcement.
