Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill advertises and requires live network access to fetch Polymarket leaderboard and wallet position data, but it does not declare any corresponding permissions. Undeclared network capability is a real security issue because it prevents users and hosting platforms from accurately understanding or constraining the skill’s external communication surface, which can enable unexpected data exfiltration, tracking, or interaction with untrusted remote services.
