Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill performs network requests and may access environment-backed tooling, but it declares no permissions. That mismatch weakens review and enforcement because operators and policy engines cannot accurately understand or restrict what the skill can do. In this context, the skill sends wallet addresses to local and external services, so undeclared capabilities materially affect privacy and governance.
