Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security checks across malware telemetry and agentic risk
This is a real-money trading skill whose main purpose is disclosed, but it includes runnable mainnet examples that can place trades or change leverage without strong warnings or confirmation gates.
Install only if you intend to work with live algorithmic trading. Treat every live example as capable of using real funds, review is_testnet settings, trade sizes, symbols, margin mode, and leverage before execution, and never commit or share .env files or private keys.
66/66 vendors flagged this skill as clean.