Undeclared Tool Scope
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
The skill instructs the user to run local scripts that read exported conversation files, write a SQLite database, access environment variables for an API key, and send conversation contents over the network to OpenAI for embedding, but it declares no explicit tool scope or permissions. This creates a security transparency and least-privilege problem: operators cannot easily tell from the manifest that the skill handles sensitive local data and performs external data exfiltration to a third-party API.
- Content
