Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill instructs users to export Bitfinex API credentials into environment variables and then run a script that uses network access, but the skill declares no permissions. This creates a transparency and governance gap: users and platforms cannot accurately assess that the skill will access secrets from the environment and send authenticated requests to an external service, increasing the risk of accidental secret exposure or unsafe execution in broader agent environments.
