Commit 2b408ee
fix(lp3): remediation and docs name allowed-tools for SKILL.md (#316)
LP3's detection logic accepts `allowed-tools` as a valid tool-scope
declaration, but the runtime remediation string, the pattern-defaults
fallback, and docs/B.3.1 still directed authors to add a `permissions`
field. For Claude Code / Agent Skills SKILL.md, `permissions` is not part
of the frontmatter schema and is ignored as unknown, so following the
advice could never resolve the finding.
Aligned the three user-facing strings with the code:
- LP3 remediation (analyzer + pattern_defaults): declare `allowed-tools`
in SKILL.md frontmatter, or a `permissions` list in MCP server
manifests, stating which applies to which manifest type.
- LP3 finding message + description: "declares no tool scope
('permissions' or 'allowed-tools')" instead of "no declared
permissions", matching the actual trigger condition.
- docs/B.3.1 LP3 section: Triggers when / Example / Remediation updated
the same way.
No behavior change; detection logic untouched. tests/test_mcp_least_privilege.py 15/15.
Closes #313
Signed-off-by: ppcvote <risky9763@gmail.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>1 parent 5302b5f commit 2b408ee
3 files changed
Lines changed: 19 additions & 10 deletions
File tree
- docs
- src/skillspector/nodes/analyzers
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
160 | 160 | | |
161 | 161 | | |
162 | 162 | | |
163 | | - | |
164 | | - | |
| 163 | + | |
| 164 | + | |
| 165 | + | |
165 | 166 | | |
166 | 167 | | |
167 | 168 | | |
168 | 169 | | |
169 | 170 | | |
170 | 171 | | |
171 | | - | |
172 | | - | |
| 172 | + | |
| 173 | + | |
| 174 | + | |
173 | 175 | | |
174 | | - | |
175 | | - | |
| 176 | + | |
| 177 | + | |
| 178 | + | |
| 179 | + | |
| 180 | + | |
176 | 181 | | |
177 | 182 | | |
178 | 183 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
312 | 312 | | |
313 | 313 | | |
314 | 314 | | |
315 | | - | |
| 315 | + | |
| 316 | + | |
316 | 317 | | |
317 | 318 | | |
318 | 319 | | |
| |||
323 | 324 | | |
324 | 325 | | |
325 | 326 | | |
326 | | - | |
| 327 | + | |
| 328 | + | |
| 329 | + | |
| 330 | + | |
327 | 331 | | |
328 | 332 | | |
329 | 333 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
121 | 121 | | |
122 | 122 | | |
123 | 123 | | |
124 | | - | |
| 124 | + | |
125 | 125 | | |
126 | 126 | | |
127 | 127 | | |
| |||
380 | 380 | | |
381 | 381 | | |
382 | 382 | | |
383 | | - | |
| 383 | + | |
384 | 384 | | |
385 | 385 | | |
386 | 386 | | |
| |||
0 commit comments