Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill explicitly documents reading and writing a local JSON file to persist token logs, but the metadata does not declare any permissions for those file operations. That creates a transparency and policy-enforcement gap: users or platforms may authorize the skill under the false assumption that it does not touch the filesystem, while it can still persist potentially sensitive usage telemetry.
