Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill instructs the agent to write scraped comment data and generated reports to local disk, but the metadata declares no corresponding permissions. Undeclared file I/O weakens user/admin visibility into what the skill can persist locally and increases the risk of silent data collection or unintended storage of sensitive content.
