Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill documentation describes file-writing behavior via learned_patterns.json and possibly modifying SKILL.md, yet no permissions are declared. Undeclared write capability is dangerous because it can surprise operators, bypass least-privilege expectations, and enable persistence or tampering if the skill is run in a broader agent environment.
