Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill explicitly instructs the agent to inspect, back up, export, and update MemoryOS files, which implies read/write access to local storage, but it does not declare corresponding permissions. Undeclared file access weakens transparency and policy enforcement, making it easier for a caller or orchestrator to invoke a skill that can modify persistent long-term memory without clear consent or sandboxing expectations.
