Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill documentation indicates capabilities to read environment variables and access the network, yet it does not declare corresponding permissions. This creates a transparency and governance problem: users and hosting platforms may underestimate the skill's access to secrets and external services, especially since it handles a private key and submits on-chain transactions. In a fund-managing DeFi skill, undeclared env/network access materially increases risk because secrets exposure or unexpected external calls could affect real assets.
