Undeclared Tool Scope
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
The skill instructs use of a Python script that reads user-supplied input files and writes output files, but the manifest declares no explicit tool scope or permissions. This creates an avoidable trust gap: an agent may be allowed broader file access than the skill actually needs, increasing the chance of unintended file reads/writes or abuse if the skill is invoked with sensitive paths.
- Content
