Undeclared Tool Scope
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
The skill instructs the agent to read uploaded files, write a Python script into the session filesystem, persist progress files, and generate an HTML report, but it declares no explicit tool scope or allowed-tools boundary. This creates an avoidable over-privilege condition: if the runtime grants broader file or environment access than intended, the skill can read, write, and potentially expose sensitive local/session data beyond the minimum required for feasibility review.
- Content
