Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill documentation instructs use of environment variables for API credentials and references reading and writing local files for configuration, audit logs, and safety controls, but it does not declare any explicit permissions. Undeclared access to env, file_read, and file_write weakens reviewability and can hide sensitive data exposure or state changes, which is especially risky in a trading skill that handles API secrets and can influence financial actions.
