Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill instructs the agent to execute a CLI that uses a wallet private key from environment variables and performs networked blockchain operations, yet it declares no permissions or safety boundaries. This creates a real capability/consent mismatch: an operator or higher-level system may treat the skill as low-risk while it can sign transactions, move funds, and interact with mainnet/testnet.
