Undeclared Tool Scope
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
The skill clearly instructs use of file access and networked operations, including reading local files for upload workflows and invoking external endpoints, but it does not declare any explicit tool scope or allowed-tools policy. This creates an authorization gap: an agent runtime may grant broader file or network capabilities than intended, making it easier for prompt injection, misconfiguration, or future skill changes to trigger overbroad access.
- Content
