Undeclared Tool Scope
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
Without declared permissions the skill's intent is opaque and cannot be validated.
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This is a straightforward local invoice PDF generator, with the main caution that generated invoices can contain sensitive billing and bank details and are written to disk.
Before installing, be comfortable with a local Node script that reads invoice JSON/config files and writes a PDF containing customer and payment details. For real invoices, avoid shared temp locations, set outputDir to a private secured directory, protect any config containing IBAN/SWIFT details, and delete generated PDFs when no longer needed.
Without declared permissions the skill's intent is opaque and cannot be validated.
The skill explicitly writes invoice PDFs to disk and invoices commonly contain sensitive personal and financial data, including customer addresses, account references, and bank details. Omitting a warning about this storage behavior can lead users to place regulated or confidential billing data into insecure locations such as shared /tmp directories or persistent volumes without appropriate handling.
The script accepts input.outputDir and writes the generated PDF to that path without restriction. If untrusted input can reach this field, the skill can be abused as a file-write primitive to place sensitive invoices or overwrite files in arbitrary writable locations on the host filesystem, which exceeds the intended narrow invoice-generation scope.
The script persists full invoice PDFs containing customer names, addresses, invoice numbers, and payment details to local disk by default, but gives no warning or control around retention. In constrained or shared environments, this can lead to unintended storage of sensitive billing data where other users, processes, backups, or logs may later access it.
The manifest describes a plain Node.js PDF invoice generator with custom branding and payment details, but does not indicate any need to inspect process environment or load configuration from arbitrary external paths. Reading process.env.INVOICE_CONFIG and supporting an override path via configuration introduces ambient host-state dependency beyond the core document-rendering role.
No suspicious patterns detected.