Undeclared Tool Scope
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
The skill declares no allowed tool scope, yet its workflow instructs the agent to execute a local Python script via shell. That creates a permissions/behavior mismatch: an orchestrator or reviewer cannot clearly determine that shell execution is intended, which increases the risk of unintended command execution or over-privileged invocation if the skill is enabled.
- Content
