Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill advertises persistent memory features that inherently require filesystem access and optional network access to Ollama, but the manifest does not clearly declare those capabilities or warn about them. Undeclared network and shell-capable behavior reduces operator visibility and can bypass expected trust boundaries, especially for an agent plugin that auto-processes conversation content.
