Undeclared Tool Scope
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
The skill instructs use of local Python scripts plus outbound HTTP calls and implicitly relies on environment variables, file reads/writes, network access, and shell execution, but it declares no explicit tool scope or permission boundaries. In an agent environment, this increases the chance of overbroad tool access, accidental data exposure through env vars or filesystem access, and unintended network actions beyond the minimum required for rendering graphics.
- Content
