Undeclared Tool Scope
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
The skill clearly instructs use of shell-capable commands such as
openclaw config set,openclaw doctor, and RPC calls, but it does not declare any explicit tool scope or allowed-tools boundary. That creates an authorization ambiguity where an agent may invoke shell operations more broadly than intended, increasing the chance of unsafe command execution or unintended modification of local configuration and state.- Content
