Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The manifest advertises an automaton that monitors RSS feeds and can trade, but it does not declare the sensitive capabilities it clearly relies on: environment access for API keys, network access for feeds and trading APIs, and file read/write for local state in /tmp. Missing permission declarations reduce transparency and can bypass user/operator expectations about what the skill is allowed to access, which is especially risky for an automated trading workflow.
