Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill advertises executable commands and API usage that read session files and appear to generate reports and maintain state, yet the skill manifest does not declare any permissions. This creates a transparency and governance gap: users and orchestrators cannot accurately assess or constrain file access, which is especially risky for a context-management skill that may touch sensitive conversation history and memory data.
