Undeclared Tool Scope
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
The skill includes shell command examples invoking external endpoints via a helper script, but it does not declare an explicit tool scope such as allowed-tools or permissions. That creates an authorization ambiguity where an agent runtime may permit broader shell/network use than intended, increasing the chance of unintended external requests or command execution beyond this narrow research workflow.
- Content
