Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill instructs the agent to write persistent persona data into SOUL.md, which is a file-write capability, yet no permissions are declared. Undeclared write behavior weakens user consent and platform enforcement because a user may believe this is only an analysis skill, while it can also modify local state and future assistant behavior.
