Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill invokes a Python script that creates, updates, exports, imports, and deletes deck files, which is a file-write capability, yet no corresponding permission or user-facing disclosure is declared. Hidden write access increases risk because a user may invoke a seemingly harmless study feature without realizing it persists or modifies local data in the home directory.
