Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill documents use of environment variables and outbound RPC/network access, but no permissions are declared. In an agent setting, undeclared access to secrets and network resources weakens sandboxing and informed consent, making it easier for the skill to exfiltrate wallet material or perform unintended remote actions. Because this is a wallet skill handling private keys, missing permission declarations are more dangerous than in ordinary utility skills.
