Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill advertises no explicit permissions, yet the documented file structure and behavior indicate it can write files, such as generating Markdown backtest reports. Undeclared write capability reduces transparency and prevents users or the platform from making an informed trust decision, which can enable unexpected local file modification.
