Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill clearly instructs the agent to use shell-based capabilities via curl and a sourced helper script, yet it declares no explicit permissions. In a trading skill, undeclared shell access is especially risky because it can place orders, access account data, and interact with credentials-bearing environment variables without an upfront permission boundary or user visibility.
