Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill declares use of a high-value credential (`SIMMER_API_KEY`) and describes live trading behavior, but the metadata shown does not declare explicit permissions despite requiring environment access. This creates a transparency and governance gap: a user or platform may underestimate the skill's ability to read secrets and place trades, increasing the risk of credential misuse or accidental authorization of financial actions.
