Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill explicitly relies on the `SIMMER_API_KEY` environment variable, which is a sensitive trading credential, yet the static analysis indicates no corresponding declared permissions. That creates a security governance gap: reviewers and execution platforms may not understand that the skill needs access to secrets, increasing the chance of over-broad secret exposure or unsafe deployment assumptions.
