Undeclared Tool Scope
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
Without declared permissions the skill's intent is opaque and cannot be validated.
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a focused Junqi layout helper that validates and renders game boards locally, with no evidence of hidden access, persistence, network use, or destructive behavior.
Install this if you want a Chinese-language Junqi layout generator with local validation and image rendering. Be aware that it enforces some opinionated strategy constraints, so it may reject layouts that another Junqi player might consider acceptable.
Without declared permissions the skill's intent is opaque and cannot be validated.
This Python file contains multiple hard-coded Chinese strings used in rendered output and defaults, such as the banner text and cell labels. Because the skill does not offer a language or locale choice, it appears to enforce a specific language in a way that can violate language/locale policy requirements.
This section goes beyond strict validation and embeds subjective heuristics, including the fixed HQ composition rule and the 'important pieces not trapped' logic. In a skill whose description promises strict hard-rule validation, mixing policy and heuristic logic can silently bias outputs, reject legal user input, and undermine any security or workflow decisions that rely on validator results as objective truth.
The validator is presented as performing hard-rule legality checks, but this block enforces a specific strategy choice: the two HQ cells must be exactly 军旗 and 排长. That creates an integrity issue because valid layouts can be rejected or manipulated according to an undocumented preference, which is especially risky when downstream components trust the validator as an authoritative legality gate.
No suspicious patterns detected.