Undeclared Tool Scope
- Category
- MCP Least Privilege
- Confidence
- 78% confidence
- Finding
The skill documentation defines installation and execution steps for a Node.js/WASM CLI and static analysis detected capabilities including environment access, file reads, network, and shell, but the skill declares no explicit tool scope such as permissions or allowed-tools. In an agent setting, this can lead to overbroad execution authority where the agent may invoke shell commands or access files beyond what is necessary for geometry processing, increasing the chance of unintended data exposure or command execution.
- Content
