Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill explicitly instructs reading from and writing to local files (`references/food_data.json` and `references/meal_log.json`) but does not declare corresponding permissions. Undeclared file access weakens least-privilege guarantees and can lead to unauthorized persistence of sensitive user dietary/health data or unexpected filesystem access if the runtime grants broader capabilities than users expect.
