Undeclared Tool Scope
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
The skill documentation describes a Python CLI that reads and writes a local JSON database (
~/.posture_patrol.json), but the manifest does not declare any explicit tool scope or permissions. This creates a trust and policy gap: a host or reviewer cannot easily tell that filesystem access is required, and an over-permissive runtime could allow unintended file access beyond the expected posture data file.- Content
