Undeclared Tool Scope
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
Without declared permissions the skill's intent is opaque and cannot be validated.
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This skill coherently generates local DOCX equity research reports, with ordinary file-output risks but no evidence of hidden execution, exfiltration, persistence, or privilege misuse.
Install only if you want a local Python-based DOCX report generator. Confirm the output path before running because it can create or overwrite DOCX files, avoid embedding private local images unless intended, and review branding/disclaimer text before sharing reports externally.
Without declared permissions the skill's intent is opaque and cannot be validated.
The invocation description is very broad and can cause the skill to trigger for many finance-related requests without clear boundaries or confirmation steps. Over-broad activation increases the chance of unintended file generation, processing sensitive investment data, or misuse in contexts where the user did not explicitly request document creation.
The API and CLI documentation state that the skill writes a .docx file to a caller-specified path, but the skill description does not warn users that it performs filesystem writes. Hidden or implicit write behavior can surprise users, overwrite existing files, or create sensitive reports on disk in shared or monitored environments.
Suspicious Unicode normalization or mixed-script content
This .py file contains user-facing natural-language documentation that defaults to Chinese for the module description and usage context. Under the policy rule for language/locale choice, forcing a specific language without opt-in can be a policy concern, especially because the API surface advertises a configurable language parameter.
The main make_report docstring frames file output responsibility narrowly around the final .docx path, but the implementation also creates temporary chart image files via tempfile.mkstemp during chart rendering and analysis sections. This is not just omitted detail in one helper; the public entrypoint documentation gives a materially incomplete impression of write behavior while the code performs additional filesystem writes.
The argument parser sets --language to zh by default, which imposes a specific language choice unless the user explicitly overrides it. Under the policy, forcing a language or locale without opt-in is a natural-language policy concern.
No suspicious patterns detected.