Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill instructs the agent to create a local `finance-news/` directory for caches and reports, which is a file-write capability, but no corresponding permission is declared. Undeclared write access weakens sandboxing and user transparency, and could allow unexpected persistence of fetched content or generated reports beyond what a reviewer expects from the manifest.
