Undeclared Tool Scope
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
The skill reads local JSON artifacts but does not declare any explicit tool scope such as permissions or allowed-tools. Even though the documented purpose is limited to auditing GitHub Actions run exports, the lack of scope declaration weakens least-privilege controls and can allow broader-than-expected file access if the execution environment grants it.
- Content
