Undeclared Tool Scope
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
The skill explicitly describes file read/write behavior via a local JSON state file, lock sidecar, and per-application lock files, but it does not declare any tool scope such as permissions or allowed-tools. That mismatch can let an agent invoke filesystem-capable tools without an explicit contract, weakening least-privilege controls and making unintended local state modification more likely.
- Content
