Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 73% confidence
- Finding
- The skill documentation indicates local file read/write capabilities but does not declare them as permissions, which creates a transparency and trust problem for users and for any permission-gating system. In this context, the writes are especially sensitive because the broader skill behavior includes storing device serials, credentials, and IP addresses in local configuration, so undeclared persistence can expose secrets or bypass expected review controls.
