Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill explicitly requires a raw PRIVATE_KEY in environment variables and is marked as high-privilege, yet it does not declare corresponding permissions. This creates a dangerous transparency and governance gap: users or hosting platforms may underestimate the access level, while the skill can authorize arbitrary wallet transactions including transfers and approvals.
