Undeclared Tool Scope
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
Without declared permissions the skill's intent is opaque and cannot be validated.
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This is a self-contained vehicle-parts sourcing reference skill that reads local JSON data and shows no network, credential, persistence, or destructive behavior.
Before installing, treat the sourcing data as reference material and independently verify supplier claims, certifications, and current market figures before making business decisions. The skill itself appears limited to reading bundled data and returning guidance.
Without declared permissions the skill's intent is opaque and cannot be validated.
No suspicious patterns detected.