Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 77% confidence
- Finding
- The skill advertises behavior that includes writing to persistent state (`self-reflection-loop`, learner injection, statistics/memory updates) but declares no permissions. Undeclared write capability is dangerous because it obscures the skill’s real side effects, preventing users or a runtime policy engine from making an informed trust decision and enabling unauthorized persistence or tampering if the skill is executed.
