Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill declares no permissions, yet its metadata and installation instructions indicate it writes to local files such as AGENTS.md and SOUL.md. Undeclared file-write capability is dangerous because it can silently alter agent routing or persistence behavior, reducing auditability and enabling policy changes outside the expected permission model.
