Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill accesses credentials from environment variables and local files, then uses them to make authenticated network requests to Binance, but it does not declare corresponding permissions. This creates a transparency and consent problem: an agent may invoke a highly privileged trading skill without clear permission gating, increasing the risk of unauthorized account access and financial actions.
