Undeclared Tool Scope
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
The skill explicitly drives network access and shell execution via a Python downloader and yt-dlp, but it does not declare any tool scope or permission boundaries. In an agent setting, this weakens security controls and user transparency, increasing the chance the skill can perform broader-than-expected actions such as network fetching and local command execution without clear policy gating.
- Content
