Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill instructs the agent to read from and write to the workspace by creating and updating `.deepresearch/<slug>/` state and invoking `scripts/deepresearch.py`, but it does not declare any corresponding permissions. This creates a capability/permission mismatch that can bypass operator expectations, making persistent file modification possible without explicit review; in this context, the resumable ledger design increases exposure because repeated writes are a core workflow feature.
