Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill declares no permissions, yet its documented structure and behavior imply file reads from references/ and writes to logs/evolution_log.md via supporting scripts. Undeclared read/write capabilities weaken transparency and consent boundaries, making it easier for a seemingly harmless divination skill to access or persist data beyond user expectations.
