Undeclared Tool Scope
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
Without declared permissions the skill's intent is opaque and cannot be validated.
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This skill provides context-management guidance and local audit utilities; its file reading and report-writing behavior is purpose-aligned and disclosed enough to treat as benign with caution.
Install only if you want an agent to help organize and audit local context. Before running the scripts or adopting the template, choose session directories deliberately, avoid including secrets or private logs unless necessary, review where audit reports and resume briefs will be written, and tighten the template rules for sensitive projects.
Without declared permissions the skill's intent is opaque and cannot be validated.
Skill injects content designed to persist in agent memory or context across interactions. Persistent injection can alter agent behavior long after the initial interaction.
For long-running tasks, keep the most important constraints in a
durable location or use the runtime's supported mechanism for
persistent instructions.
Do not repeatedly duplicate the entire instruction set.
Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.
Tool outputs are the single largest source of context bloat in most
sessions. A single `read_file` on a large source file can consume 30%
of the context window. Twelve log files can fill the window entirely.
The rule: **any tool output larger than 2,000 tokens must be
summarized before it enters context.**
Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.
"If the model supports 1M tokens, use 1M tokens."
The manifest describes a skill for diagnosing and improving context usage in AI agent sessions, which implies analysis of session artifacts. This implementation also creates a persistent audit directory under ~/.context-engineering/audits and saves JSON reports there by default, which is additional file-writing behavior not indicated by the description.
The on_demand load rule relies on broad topic-keyword matching and task dependency, which is underspecified and can cause overloading of irrelevant reference material or loading sensitive/internal files too eagerly. In a context-management skill, that ambiguity directly undermines the stated goal of minimizing context and can be exploited by crafted prompts that mention many keywords to force unnecessary context inclusion.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
# Rules express precedence and policy. They resolve conflicts between
# tiers and prevent common architectural mistakes.
#
# Write rules as imperative sentences. Each rule should be testable —
# a reviewer should be able to say "yes, this session followed that
# rule" or "no, it did not."
The rule to load a skill only if its description matches the active task is too vague to enforce safely, because 'matches' is undefined and can be stretched by adversarial or merely noisy task descriptions. In an agent environment, ambiguous skill-selection criteria can trigger unnecessary or inappropriate skill loading, expanding the instruction surface and increasing the chance of prompt-conflict or misuse.
Mandating that the final action of every session is to write context/resume-brief.md introduces automatic persistence of session-derived content without any disclosure, consent, or data-minimization guardrails. This can capture sensitive prompts, user data, secrets, or proprietary material and store them beyond the active session, creating privacy and retention risk.
The emergency compression action instructs the agent to cache all tool outputs to disk, but provides no warning about persistence, sensitivity classification, access control, or redaction. Tool outputs commonly contain credentials, internal code, logs, or personal data, so unconditional disk caching can materially increase exposure and retention risk.
This code creates an output directory and writes an audit JSON report containing derived information from session artifacts, which may include sensitive conversation or system-context metadata. While the CLI has an --output-dir option, there is no explicit warning in code comments, prompts, or user-facing output before the write occurs to make persistence of potentially sensitive audit results clear.
The manifest frames the skill as diagnosing and improving context usage in agent sessions. The compare mode depends on enumerating previously saved reports from a persistent local store and introduces longitudinal report-management behavior that is not obviously required by that purpose as stated.
No suspicious patterns detected.