Undeclared Tool Scope
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
The skill invokes shell/Python, uses an API key from the environment, and performs network access, but it does not declare an explicit tool scope or permissions boundary. That increases the chance the agent can execute this skill with broader-than-necessary capabilities, making accidental secret exposure, unintended command execution, or unauthorized network use harder to constrain or audit.
- Content
