Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill clearly documents access to environment variables for credentials and network/RPC/API interactions, yet it declares no permissions. This weakens platform trust boundaries because users and orchestrators are not accurately informed that the skill can read secrets and communicate with external services, including blockchain RPCs and Privy APIs.
