Undeclared Tool Scope
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
The skill references a local JSON store and invokes a Python script that reads and writes files, but it does not declare any explicit tool scope such as permissions or allowed-tools. That creates an under-specified trust boundary: an agent may infer broader filesystem access than intended, and future changes to the script could expand file operations without any policy guardrails.
- Content
