Undeclared Tool Scope
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
The skill invokes a bundled Python script that uses network access and can read environment configuration, but the manifest does not declare any tool scope or allowed-tools restrictions. This creates an unclear trust boundary: an agent may activate the skill without explicit disclosure that it will execute code with network capability, increasing the chance of unintended outbound requests or access to sensitive environment-derived configuration.
- Content
