Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill requires access to a highly sensitive environment variable, `WALLET_PRIVATE_KEY`, but does not declare explicit permissions beyond metadata requirements. That creates a transparency and consent gap: an agent or user may not appreciate that the skill can directly spend funds by signing payments with a wallet key. In this context, undeclared secret access is security-relevant because the skill's core behavior includes automated micropayments.
