Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill explicitly performs outbound HTTP requests to public Polymarket endpoints but does not declare any corresponding network permission. Undeclared network capability is a real security issue because it weakens user/admin review, breaks least-privilege expectations, and could enable unnoticed data exfiltration or remote content retrieval if the implementation changes.
