Undeclared Tool Scope
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
The skill clearly expects access to environment variables, network egress, and file output, but it does not declare any explicit tool scope or permission boundaries. This creates an over-privilege and transparency problem: an agent may invoke the skill without users understanding that prompts will be sent externally, API keys will be read from the environment, and reports may be written to disk.
- Content
