Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill documentation clearly implies capabilities to read environment variables, access local files, write configuration/logs, and make network requests, yet no permissions are declared. In an agent ecosystem, this creates a transparency and consent failure: users may install or run a trading skill without understanding that it can access secrets, persist data, and communicate externally to exchanges/webhooks.
