Undeclared Tool Scope
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
The skill advertises operational steps that can involve live MCP searches, reading workflow/data files, and generating an HTML report, but it does not declare an explicit tool permission boundary such as allowed tools or permissions. In an agent runtime, this can lead to overbroad access to network, filesystem, or environment capabilities beyond what the skill actually needs, increasing the blast radius if the skill is misused, modified, or combined with prompt injection elsewhere.
- Content
