Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill directs use of local scripts, file generation, and live quote retrieval, which implies file read/write and network capabilities, but it does not declare permissions explicitly. In a trading workflow, undeclared capabilities reduce transparency and can bypass expected operator review, increasing the risk of unintended data access, local artifact leakage, or outbound requests during sensitive financial operations.
