Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill instructs the agent to run a cleanup script that modifies `sessions.json`, which is a file-write capability, but the skill declares no permissions. This creates a permission-model mismatch: an agent may perform state-changing filesystem operations without explicit disclosure or gating, increasing the risk of unintended deletion of session metadata, especially with the `--all` mode.
