Undeclared Tool Scope
- Category
- MCP Least Privilege
- Confidence
- 97% confidence
- Finding
The skill describes operations that require sensitive capabilities including shell execution, filesystem reads/writes, environment-variable access, and possible network use, but it does not declare any explicit tool scope such as permissions or allowed-tools. This creates an overbroad execution surface where an agent may invoke more capabilities than intended, increasing the risk of unauthorized file modification, credential exposure via environment access, or unsafe command execution during installation and task registration.
- Content
