Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill advertises itself as a documentation-driven trading assistant, yet the analyzed behavior indicates access to environment variables, filesystem read/write, network, and shell capabilities without an explicit permissions declaration. This creates a hidden trust boundary: users may enable a seemingly advisory skill that can also modify local files, invoke commands, fetch remote content, and potentially access secrets, making supply-chain compromise or unintended host-side actions much more dangerous.
