Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill declares required binaries and environment variables, but does not declare permissions while clearly describing network access and use of sensitive environment material (`FLO_PRIVATE_KEY`). That mismatch can cause the agent platform or reviewer to underestimate the skill's real privileges, especially because the skill can send messages, broadcast blockchain transactions, and contact remote supernodes. In this context, hidden capability is materially risky because the skill is a high-impact financial and messaging interface.
