Undeclared Tool Scope
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
The skill requires environment access to read an API key and network access to call a third-party service, but it does not declare any explicit tool scope such as permissions or allowed-tools. That increases the attack surface because a host may grant broader capabilities than necessary, making it harder to enforce least privilege and easier for a compromised or modified implementation to access unintended tools or destinations.
- Content
