Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill instructs writing note content to /tmp/note_content.txt and creating Apple Notes entries, but no explicit permissions or capability declaration is present. Undeclared file-write behavior is dangerous because users and hosting platforms cannot accurately assess what local data the skill modifies, and temporary files in shared locations can expose sensitive transcript contents to other local processes or users.
