Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill explicitly instructs users to run a script that queries Polymarket's public API, which means it performs network access, yet no permissions are declared in the skill metadata. Undeclared network capability weakens review and runtime governance because consumers may not realize the skill can send outbound requests to external infrastructure.
