Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 82% confidence
- Finding
- The skill advertises and demonstrates behavior that observes user activity, imports history, and generates automations, yet it declares no explicit permissions while static analysis detected file read/write capabilities. This creates a trust and sandboxing gap: operators may approve the skill without understanding that it can access or persist user-derived data, increasing the risk of unauthorized collection, retention, or modification of workflow/history data.
