Undeclared Tool Scope
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
The skill explicitly instructs the agent to read local reference files such as
references/core_workflow.md, but it does not declare any corresponding tool scope or file-read permission boundary. This creates an authorization mismatch: an agent/runtime may still attempt local file access implicitly, which can lead to unintended access to adjacent files, hidden prompts, or sensitive workspace content if path handling or policy enforcement is weak.- Content
