Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 85% confidence
- Finding
- The skill documentation instructs use of environment-backed secrets and private-key-driven operations, but it declares no permissions or security boundaries. In an agent ecosystem, hidden env access and undeclared secret handling increase the chance that a caller or runtime grants broader access than users expect, especially when blockchain private keys and signer keys are involved.
