Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill invokes a Python script that queries an external API, so it has network capability, but the manifest does not declare any tool scope such as permissions or allowed-tools. This is a real security hygiene issue because undeclared network access reduces transparency and weakens policy enforcement, even though the documented behavior is read-only and limited to public Polymarket data.
