Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill performs file-write behavior by instructing the agent to save generated passwords to `memory/passwords.md`, but no corresponding permission or disclosure is declared. This is dangerous because it introduces silent persistent storage of sensitive secrets, expanding the attack surface and violating least-privilege expectations for a password-generation tool.
