Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill document describes capabilities to read environment variables, read local files, and access networked APIs, but the manifest does not declare corresponding permissions or constraints. This creates an authorization gap: a reviewer or execution framework may underestimate what the skill can access, including local secrets and external services, which is especially risky in a trading/daemon-management context.
