Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill advertises operational capabilities involving wallets, RPC access, WebSocket subscriptions, bridging, swaps, and headless signing, yet the file declares no explicit permissions. That mismatch can cause the runtime or user to underappreciate that network access and environment-backed secrets may be used, weakening transparency and consent around sensitive operations.
