Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill requires access to a sensitive environment variable (`ONCHAT_PRIVATE_KEY`) for write operations, but this capability is not explicitly declared in permissions. Undeclared secret access is dangerous because it obscures the trust boundary from users and reviewers, and the private key can authorize irreversible on-chain transactions and spending.
