Undeclared Tool Scope
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
The skill declares executable behavior that reads local files via a shell script and globbed JSON inputs, but it does not define any explicit tool scope such as permissions or allowed-tools. Without a declared scope, an agent framework may grant broader-than-necessary file access, increasing the chance of unintended data exposure if the script is invoked in a sensitive workspace.
- Content
