Undeclared Tool Scope
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
The skill instructs the agent to invoke a local Python script, read Markdown and template files, write DOCX output, and rely on shell-executed tooling via pandoc, but it declares no explicit tool scope such as allowed-tools or permissions. This creates an authorization gap where an agent may execute file and shell-capable actions without a clearly constrained contract, increasing the chance of overbroad file access or unsafe command use when handling user-supplied paths and templates.
- Content
