Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill exposes sensitive capabilities including environment-variable access, outbound network requests, and local file writes, yet it does not declare permissions in a machine-readable way. That mismatch can cause agents or policy engines to invoke it without understanding that it can access wallet secrets, write plaintext key material, or send arbitrary paid requests, increasing the risk of unintended secret exposure or financial loss.
