Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill explicitly declares use of the `SIMMER_API_KEY` environment variable but the metadata shown does not declare corresponding permissions. Undeclared access to sensitive environment data weakens least-privilege controls and can enable credential exposure or unauthorized trading if the runtime grants broader env access than intended.
