Undeclared Tool Scope
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
Without declared permissions the skill's intent is opaque and cannot be validated.
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent read-only prediction-market data skill, with wallet lookups that users should treat as privacy-sensitive.
Use this skill only if you are comfortable sending prediction-market searches, market IDs, wallet addresses, and your AISA API key to AIsa. Avoid querying third-party wallets unless you have a legitimate, authorized reason, and monitor API usage because the documentation states a per-query cost.
Without declared permissions the skill's intent is opaque and cannot be validated.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
class PredictionMarketClient:
"""Cross-Platform Prediction Market Data - AIsa API Client."""
BASE_URL = "https://api.aisa.one/apis/v1"
def __init__(self, api_key: Optional[str] = None):
self.api_key = api_key or os.environ.get("AISA_API_KEY")
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
class PredictionMarketClient:
"""Cross-Platform Prediction Market Data - AIsa API Client."""
BASE_URL = "https://api.aisa.one/apis/v1"
def __init__(self, api_key: Optional[str] = None):
self.api_key = api_key or os.environ.get("AISA_API_KEY")
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
class PredictionMarketClient:
"""Cross-Platform Prediction Market Data - AIsa API Client."""
BASE_URL = "https://api.aisa.one/apis/v1"
def __init__(self, api_key: Optional[str] = None):
self.api_key = api_key or os.environ.get("AISA_API_KEY")
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
class PredictionMarketClient:
"""Cross-Platform Prediction Market Data - AIsa API Client."""
BASE_URL = "https://api.aisa.one/apis/v1"
def __init__(self, api_key: Optional[str] = None):
self.api_key = api_key or os.environ.get("AISA_API_KEY")
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
class PredictionMarketClient:
"""Cross-Platform Prediction Market Data - AIsa API Client."""
BASE_URL = "https://api.aisa.one/apis/v1"
def __init__(self, api_key: Optional[str] = None):
self.api_key = api_key or os.environ.get("AISA_API_KEY")
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
class PredictionMarketClient:
"""Cross-Platform Prediction Market Data - AIsa API Client."""
BASE_URL = "https://api.aisa.one/apis/v1"
def __init__(self, api_key: Optional[str] = None):
self.api_key = api_key or os.environ.get("AISA_API_KEY")
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
class PredictionMarketClient:
"""Cross-Platform Prediction Market Data - AIsa API Client."""
BASE_URL = "https://api.aisa.one/apis/v1"
def __init__(self, api_key: Optional[str] = None):
self.api_key = api_key or os.environ.get("AISA_API_KEY")
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
class PredictionMarketClient:
"""Cross-Platform Prediction Market Data - AIsa API Client."""
BASE_URL = "https://api.aisa.one/apis/v1"
def __init__(self, api_key: Optional[str] = None):
self.api_key = api_key or os.environ.get("AISA_API_KEY")
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
class PredictionMarketClient:
"""Cross-Platform Prediction Market Data - AIsa API Client."""
BASE_URL = "https://api.aisa.one/apis/v1"
def __init__(self, api_key: Optional[str] = None):
self.api_key = api_key or os.environ.get("AISA_API_KEY")
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
class PredictionMarketClient:
"""Cross-Platform Prediction Market Data - AIsa API Client."""
BASE_URL = "https://api.aisa.one/apis/v1"
def __init__(self, api_key: Optional[str] = None):
self.api_key = api_key or os.environ.get("AISA_API_KEY")
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
class PredictionMarketClient:
"""Cross-Platform Prediction Market Data - AIsa API Client."""
BASE_URL = "https://api.aisa.one/apis/v1"
def __init__(self, api_key: Optional[str] = None):
self.api_key = api_key or os.environ.get("AISA_API_KEY")
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
class PredictionMarketClient:
"""Cross-Platform Prediction Market Data - AIsa API Client."""
BASE_URL = "https://api.aisa.one/apis/v1"
def __init__(self, api_key: Optional[str] = None):
self.api_key = api_key or os.environ.get("AISA_API_KEY")
This code sends user-supplied wallet identifiers and related filters to a remote service via HTTP requests, which can expose potentially sensitive financial-activity data to a third party. While network access is part of the client’s purpose, there is no confirmation prompt or explicit user-facing disclosure in the execution flow that wallet-related inputs will be transmitted externally.
The skill explicitly encourages tracking wallet positions and P&L by wallet address without warning that wallet addresses can reveal sensitive financial behavior and can often be linked to real identities through correlation. In an agent setting, this omission can normalize surveillance-style lookups of third-party wallets and lead to privacy-invasive use of on-chain financial data.
This endpoint transmits a wallet address to a third-party API to retrieve user activity, which can expose trading behavior and financial history associated with that address. In combination with the skill's lack of privacy guidance, this creates a real privacy risk for users or third parties whose wallet addresses are queried without informed consent.
# Fetch activity data for a specific user
curl -X GET "https://api.aisa.one/apis/v1/polymarket/activity?user={wallet_address}" \
-H "Authorization: Bearer $AISA_API_KEY"
This endpoint sends a wallet address to a third-party service to retrieve all positions, revealing potentially sensitive holdings and exposure for that wallet. Because the documentation encourages this capability without a consent or privacy warning, it materially increases the risk of invasive profiling of individuals or entities.
# Fetch all Polymarket positions for a proxy wallet address
curl -X GET "https://api.aisa.one/apis/v1/polymarket/positions/wallet/{wallet_address}" \
-H "Authorization: Bearer $AISA_API_KEY"
Fetching wallet information by address sends potentially identifying financial metadata to an external provider and facilitates aggregation of on-chain identity information. In an autonomous-agent context, such lookups can occur at scale and without clear user awareness, making the privacy exposure more significant.
# Fetch wallet information
curl -X GET "https://api.aisa.one/apis/v1/polymarket/wallet?eoa={wallet_address}" \
-H "Authorization: Bearer $AISA_API_KEY"
This endpoint retrieves profit-and-loss for a wallet address, which is highly sensitive financial information even if derived from public-chain activity. Sending wallet identifiers to a third-party API for P&L analysis without warning or consent can enable financial surveillance, deanonymization, and profiling of trading success or losses.
# Fetch realized profit and loss (PnL) for a specific wallet address
curl -X GET "https://api.aisa.one/apis/v1/polymarket/wallet/pnl/{wallet_address}?granularity=day" \
-H "Authorization: Bearer $AISA_API_KEY"
No suspicious patterns detected.