Scope Creep
Low
- Confidence
- 93% confidence
- Finding
- The manifest declares `allowed-tools: read exec` but later also lists `write`, creating a permission mismatch that can cause reviewers or policy engines to underestimate the skill's actual capabilities. In an exec-enabled skill, undocumented write access materially increases risk because the agent could modify local files, configs, or prompts while users expect a read/exec-only tool.
