Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill documentation describes capabilities that access environment variables and external networks (`SIMMER_API_KEY`, CoinGecko, Simmer, Polymarket) but does not declare corresponding permissions. In an agent or marketplace setting, missing permission declarations reduce transparency and can cause reviewers or runners to underestimate the skill's ability to exfiltrate secrets or initiate trades over the network.
