Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill clearly relies on environment variables and outbound network access to perform wallet-funded payments, but it does not explicitly declare those permissions. This creates a transparency and policy-enforcement gap: users or platforms may enable the skill without understanding that it can access secrets and contact external services, increasing the risk of unintended spending or secret exposure if the skill behavior changes or validation is bypassed.
