Undeclared Tool Scope
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
The skill documentation instructs users to provide and use a sensitive environment variable (
ZHIPU_API_KEY), and explicitly notes that the skill reads it at runtime, but the skill declares nopermissionsorallowed-toolsscope. That mismatch weakens least-privilege controls and transparency: a host may not clearly understand that the skill needs environment access, increasing the chance of unintended secret exposure or over-broad execution rights.- Content
