Undeclared Tool Scope
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
The skill requires access to an API key, shell execution, and outbound network access, but it does not declare an explicit tool scope or allowed-tools policy. That increases the attack surface because a host agent may grant broader capabilities than necessary, making misuse of the API key or arbitrary command execution more likely if the skill is invoked in an unexpected context.
- Content
