Undeclared Tool Scope
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
The skill instructs the agent to run a local Python script that reads and writes configuration files, creates backups, and makes outbound network requests, but it declares no explicit tool scope or permissions. This creates a capability mismatch: an agent may execute sensitive file and network operations without clear user-visible constraints, increasing the chance of unintended config modification or data exposure.
- Content
