Undeclared Tool Scope
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
Without declared permissions the skill's intent is opaque and cannot be validated.
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a straightforward third-party AI API client, with the main risk being that user prompts and image URLs are sent to EVEZ's remote service.
Install this only if you are comfortable routing prompts, outputs, and image URLs through EVEZ rather than the original model provider. Do not send secrets, regulated data, private customer content, or internal image URLs without reviewing EVEZ's data handling and compliance terms.
Without declared permissions the skill's intent is opaque and cannot be validated.
The skill explicitly instructs users to send OpenAI-compatible requests to a third-party endpoint, which means prompts, outputs, and potentially sensitive application data will be transmitted off-platform. Because the skill presents this as a drop-in replacement focused on cost savings without any privacy, security, retention, or trust-boundary warning, users may unknowingly route confidential data to an unvetted service.
The chat() method sends user message content to a remote API endpoint, and the code provides no confirmation prompt, logging, or explanatory comment disclosing that user input is transmitted off-system. For a client wrapper, this data transfer is safety-relevant because prompts may contain sensitive user or system information.
The vision() method transmits both user-supplied text and an image URL to the remote EVEZ API, but the file contains no warning, comment, or prompt explaining that this information leaves the local environment. This is especially relevant because image URLs can reveal private resources or internal locations.
No suspicious patterns detected.