Undeclared Tool Scope
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
The skill instructs the agent to execute a local Python script, read Codex session logs from disk, inspect environment-dependent context such as timezone, and potentially write or emit structured output, but it declares no explicit tool scope or permissions. This creates an authorization gap: an agent may use shell and filesystem capabilities broader than necessary, increasing the chance of unintended access to sensitive local files or misuse of command execution in environments that rely on skill metadata for policy enforcement.
- Content
