Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill instructs the agent to use local scripts, read reference files, depend on environment variables and bearer tokens, and call external trading APIs, but it declares no explicit permissions. This creates a capability/permission mismatch that can undermine sandboxing, auditability, and informed deployment decisions, especially in a financial context where sensitive account data may be queried over the network.
