Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill documents file-writing behavior (`learner.py`, profile/session persistence, learned patterns) but declares no explicit permissions. This creates an authorization gap: a host or reviewer may treat the skill as lower-risk than it really is, while the skill still performs persistent writes. In a public skill that stores user-related data, hidden write capability increases the chance of unauthorized persistence or policy bypass.
