Undeclared Tool Scope
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
Without declared permissions the skill's intent is opaque and cannot be validated.
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a local social-post checker that reads user-provided draft text and reports platform-specific warnings, with no evidence of hidden execution, network access, credential use, persistence, or posting automation.
Install only if you want a local heuristic checker for draft social posts. Review its recommendations critically, especially advice about platform algorithms, reach multipliers, link placement, and shadowbans, and do not use it to evade moderation, spam controls, or platform rules.
Without declared permissions the skill's intent is opaque and cannot be validated.
The manifest description says the tool 'Scans any draft post' and presents a broad capability description, but it does not specify concrete trigger phrases, scope limits, or exclusion conditions. In a markdown/manifest context, this kind of generic wording can overlap with many normal requests about drafting or checking posts and may cause unintended invocation.
This skill is explicitly framed around exploiting 'invisible rules,' avoiding shadowbans, and maximizing distribution using claimed algorithmic penalties and multipliers. Without a warning or policy boundary, it can encourage platform-gaming, deceptive optimization, or advice that nudges users toward evasion of moderation and ranking systems.
The markdown provides command examples but does not define when the skill is intended to activate versus when general writing, editing, or social-media advice requests should not use it. For SQP-1, the absence of explicit scope constraints or negative examples can make activation conditions ambiguous.
The module documentation says the checker outputs PASS/WARN/FAIL per rule with exact fix suggestions, implying every rule result includes remediation guidance. In code, multiple PASS results and the unknown-platform error path create RuleResult objects without a fix string, so the documented output contract is broader than the actual behavior.
No suspicious patterns detected.