Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill instructs the agent to read and write multiple files (`MEMORY.md`, `memory/*`, `AGENTS.md`, `HEARTBEAT.md`) but does not declare corresponding permissions. Undeclared file access is dangerous because it hides the true capability surface from reviewers and can lead to unexpected modification of persistent agent state.
