Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill instructs use of persistent write operations via `scripts/learner.py` and explicitly says it writes logs, insights, and preferences into `learned_patterns.json`, yet no permissions are declared. Undeclared file-write capability is dangerous because it bypasses least-privilege review and can lead to silent persistence of data, configuration drift, or unauthorized modification of skill artifacts.
