Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill clearly requires access to sensitive environment variables and outbound network/RPC calls, but it does not declare those permissions explicitly. In an agent ecosystem, undeclared capabilities reduce transparency and weaken policy enforcement, making it easier for a wallet-managing skill to access secrets or initiate blockchain actions without proper review.
