Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill documentation describes network access and persistent state in ~/.config/alpha, but no permissions are declared. This creates a transparency and trust problem: users or platforms may approve the skill expecting low-risk behavior while it can read/write local files and make outbound network connections. In this context the behavior appears aligned with the stated monitoring use case, so the issue is under-declaration rather than clearly malicious functionality.
