Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill documentation describes capabilities that require environment access, file read/write, and network use, but it does not declare permissions. This creates a transparency and least-privilege problem: users and platforms cannot accurately assess what the skill will access before execution, which is especially significant because the skill handles API keys, persistent state, and live trading actions.
