Undeclared Tool Scope
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
Without declared permissions the skill's intent is opaque and cannot be validated.
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a coherent offline pool-chemistry calculator that stores only a local JSON pool log and does not show hidden network, credential, or persistence behavior.
Before installing, understand that this runs a local Python calculator and keeps your pool test history in a local JSON file. Review chemical safety guidance carefully because wrong pool measurements or misunderstood dosing advice can have real-world safety consequences, but the software behavior itself appears purpose-aligned and offline.
Without declared permissions the skill's intent is opaque and cannot be validated.
Dynamic getattr() with a non-literal attribute name can access arbitrary object attributes, potentially bypassing access controls.
def cmd_log(a, st, state):
t = {"date": a.date or date.today().isoformat()}
for k in ("fc", "cc", "ph", "ta", "ch", "cya", "salt", "borates", "temp"):
v = getattr(a, k)
if v is not None:
t[k] = v
if len(t) == 1:
No suspicious patterns detected.