Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill declares no permissions while explicitly requiring environment variables and making outbound network requests via curl. This weakens sandboxing and user awareness, increasing the chance that secrets such as API keys or wallet material are exposed to a tool with broader capabilities than declared.
