Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill advertises and relies on capabilities including environment variable access, network access, and local file read/write, but the manifest does not declare any permissions. This creates a transparency and policy-enforcement gap: reviewers and runtime controls may underestimate what the skill can do, which is especially concerning for an automated trading skill that consumes external news feeds and can act on API credentials.
