Undeclared Tool Scope
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
The skill instructs the agent to execute a Node script and use an API key plus outbound network access, but it does not declare any explicit tool scope such as allowed tools or permissions. That creates a governance gap: an agent runtime may permit broader execution or network behavior than intended, making misuse, prompt-injection chaining, or accidental overreach harder to contain.
- Content
