Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill requires both environment access (for ZAPPER_API_KEY) and network access (to call Zapper's external API), but those capabilities are not explicitly declared as permissions. This creates a transparency and policy gap: users and platforms may not realize the skill can read secrets and transmit wallet-related data off-box, increasing the risk of unintended data exposure or overly broad execution trust.
