Undeclared Tool Scope
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
The skill advertises no explicit tool scope or permission boundaries, yet the analyzer detected file-write capability in the associated implementation. That mismatch is dangerous because an agent may invoke the skill without a clear least-privilege contract, allowing unexpected filesystem modification such as overwriting local files, creating artifacts in unsafe locations, or persisting sensitive party data without the user's informed consent.
- Content
