Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill clearly directs the agent to read local memory/documentation files and exposes configurable paths for MEMORY.md and a SQLite database, but it declares no corresponding permissions or trust boundary. Undeclared file-read capability is dangerous because it can cause agents or platforms to grant broader filesystem access implicitly, reducing reviewability and increasing the chance of unauthorized access to sensitive local data.
