Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 82% confidence
- Finding
- The skill documentation clearly instructs the agent to read and write task-folder state files such as `queue.jsonl`, `progress.json`, `done.jsonl`, `failed.jsonl`, `lock.json`, and `config.env`, but no explicit permissions are declared. That mismatch creates a real security issue because consumers may trust the manifest to reflect the skill's capabilities, while the skill can still modify persistent workspace state and configuration, increasing the risk of unintended file access or tampering.
