Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill text claims inherited hooks such as learner/self-reflection and continuous self-evolution, which imply persistent state and likely file writes, but no permissions are declared. Undeclared write capability is risky because it can create or modify local files without clear user awareness or policy gating, especially in an agent ecosystem where skills may be auto-invoked.
