Undeclared Tool Scope
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
The skill instructs users to run local scripts that generate benchmark files and write runner/config/result artifacts, but the manifest does not declare any tool scope such as permissions or allowed-tools. This creates a trust and containment gap: consumers cannot tell from the skill metadata that file read/write behavior is expected, which can lead to unintended filesystem access when the skill is executed in an agent environment.
- Content
