Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill documentation describes persistent local data storage in `~/.posture_patrol.json` and stdlib-based command functionality, which implies file read/write behavior without any declared permissions. Undeclared filesystem access weakens transparency and security review because users and hosting platforms cannot accurately assess what resources the skill will touch, even if the intended use here appears limited to the user's home directory for benign tracking data.
