Undeclared Tool Scope
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
Without declared permissions the skill's intent is opaque and cannot be validated.
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a straightforward cloud text-to-speech helper that uses a DashScope API key and writes generated audio files as described.
Install only if you are comfortable using DashScope for speech synthesis. Text you synthesize is sent to that service, so do not submit secrets, private records, or confidential business content. Check the output path first because existing WAV files with the same names may be overwritten.
Without declared permissions the skill's intent is opaque and cannot be validated.
The manifest description and the entire user-facing markdown content are presented in Chinese, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking audience. This can violate language/locale policy when a skill forces a specific language without user opt-in or documented justification.
The script sends provided text to an external DashScope TTS service, which creates a privacy and data-handling risk if users supply sensitive content without realizing it leaves the local environment. Because the tool also accepts arbitrary CLI input or JSON-loaded text, confidential operational or personal data could be transmitted to a third party.
The module docstring is written entirely in Chinese and presents the skill as a general-purpose TTS tool, while the default sample text is also Chinese-only. Because the file does not offer a user language choice or explain that the skill is intentionally limited to Chinese, this appears to force a specific language/locale without opt-in.
The manifest describes a smart text-to-speech skill that retries different models/voices until synthesis succeeds. While calling a remote TTS service is expected, directly reading credentials from process environment introduces a credential-access capability that is not mentioned in the stated purpose and is broader than 'automatic model/voice retry'.
When no arguments are provided, the script defaults to generating the Chinese phrase "你好,这是智能语音合成测试". For a generic TTS skill, hardcoding a single language as the default behavior can violate language/locale policy unless the limitation is clearly documented or the user is given a choice.
The markdown states that speech is automatically saved and names a default output file, but it does not explicitly warn users that running the skill will write or overwrite data on disk. For a skill that performs file output, a brief user-facing disclosure would help set expectations about where artifacts are stored and the potential for replacing an existing file.
The file's natural-language title, comments, and default spoken text are entirely in Chinese, and the default behavior appears tailored to a single language without any visible opt-in or language-selection mechanism. Under the policy, forcing a specific language without user choice can be a locale/language policy issue unless clearly justified.
The manifest describes an intelligent speech synthesis skill that retries models/voices until success. While networked TTS itself is expected, directly reading credentials from the runtime environment is a separate capability that is not stated in the manifest and is called out as context-inappropriate in this audit model.
This code performs file writes by saving synthesized audio to output_path, but the function itself provides no prior warning, confirmation, or explanatory comment about creating or overwriting files. Although it prints after saving, that is not a pre-action disclosure, and there is no visible README/SKILL.md context in this file to warn users about the write behavior.
No suspicious patterns detected.