Skip to content

Commit 2b408ee

Browse files
ppcvoteclaude
andauthored
fix(lp3): remediation and docs name allowed-tools for SKILL.md (#316)
LP3's detection logic accepts `allowed-tools` as a valid tool-scope declaration, but the runtime remediation string, the pattern-defaults fallback, and docs/B.3.1 still directed authors to add a `permissions` field. For Claude Code / Agent Skills SKILL.md, `permissions` is not part of the frontmatter schema and is ignored as unknown, so following the advice could never resolve the finding. Aligned the three user-facing strings with the code: - LP3 remediation (analyzer + pattern_defaults): declare `allowed-tools` in SKILL.md frontmatter, or a `permissions` list in MCP server manifests, stating which applies to which manifest type. - LP3 finding message + description: "declares no tool scope ('permissions' or 'allowed-tools')" instead of "no declared permissions", matching the actual trigger condition. - docs/B.3.1 LP3 section: Triggers when / Example / Remediation updated the same way. No behavior change; detection logic untouched. tests/test_mcp_least_privilege.py 15/15. Closes #313 Signed-off-by: ppcvote <risky9763@gmail.com> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
1 parent 5302b5f commit 2b408ee

3 files changed

Lines changed: 19 additions & 10 deletions

File tree

‎docs/B.3.1-mcp-least-privilege.md‎

Lines changed: 11 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -160,19 +160,24 @@ permissions. Request only the minimum access needed.
160160
| **Confidence** | 0.70 |
161161
| **Tags** | ASI02 |
162162
163-
**Triggers when:** The manifest has no `permissions` field (or it is an empty
164-
list) **and** the analyzer detects code capabilities in executable files.
163+
**Triggers when:** The manifest declares no tool scope -- no `permissions`
164+
field (or an empty list) **and** no `allowed-tools` frontmatter -- and the
165+
analyzer detects code capabilities in executable files.
165166

166167
**Why it matters:** Without declared permissions, the skill's intent is
167168
completely opaque. Users and agents cannot evaluate whether the skill's access
168169
level is appropriate. This is less suspicious than LP1 (could be an oversight
169170
rather than deception) but still a significant transparency gap.
170171

171-
**Example:** A SKILL.md with no `permissions:` key, but the code calls
172-
`os.environ["API_KEY"]` and `subprocess.run(...)`.
172+
**Example:** A SKILL.md with neither a `permissions:` key nor an
173+
`allowed-tools:` key, but the code calls `os.environ["API_KEY"]` and
174+
`subprocess.run(...)`.
173175

174-
**Remediation:** Add a `permissions` field to SKILL.md listing the capabilities
175-
the skill requires.
176+
**Remediation:** Declare the skill's tool scope in the manifest type you are
177+
authoring. For Claude Code / Agent Skills `SKILL.md`, list the tools the skill
178+
may invoke in the `allowed-tools` frontmatter field (`permissions` is not part
179+
of the SKILL.md schema and is ignored). For MCP server manifests, add a
180+
`permissions` list naming the required capabilities.
176181

177182
---
178183

‎src/skillspector/nodes/analyzers/mcp_least_privilege.py‎

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -312,7 +312,8 @@ def node(state: SkillspectorState) -> AnalyzerNodeResponse:
312312
Finding(
313313
rule_id="LP3",
314314
message=(
315-
f"Skill has no declared permissions but code capabilities were detected: {cap_names}."
315+
f"Skill declares no tool scope ('permissions' or 'allowed-tools') "
316+
f"but code capabilities were detected: {cap_names}."
316317
),
317318
severity="MEDIUM",
318319
confidence=_clamp(0.70),
@@ -323,7 +324,10 @@ def node(state: SkillspectorState) -> AnalyzerNodeResponse:
323324
"Without declared permissions the skill's intent is opaque and cannot be validated."
324325
),
325326
remediation=(
326-
"Add a 'permissions' field to SKILL.md listing the capabilities this skill requires."
327+
"Declare the skill's tool scope: for Claude Code / Agent Skills "
328+
"SKILL.md, list the tools the skill may invoke in the "
329+
"'allowed-tools' frontmatter field; for MCP server manifests, "
330+
"add a 'permissions' list naming the required capabilities."
327331
),
328332
)
329333
)

‎src/skillspector/nodes/analyzers/pattern_defaults.py‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -121,7 +121,7 @@ class PatternCategory(StrEnum):
121121
# MCP Least Privilege (B.3.1)
122122
"LP1": "Code uses capabilities (network, shell, file write, etc.) not covered by declared permissions. The skill does more than it claims, which may indicate deceptive intent.",
123123
"LP2": "Permission list contains a wildcard ('*' or 'all'), granting blanket access with no least-privilege boundary. This disables permission-based security controls entirely.",
124-
"LP3": "Skill has no permissions field in its manifest but code uses detectable capabilities. Without declared permissions, the skill's intent is opaque and cannot be validated.",
124+
"LP3": "Skill declares no tool scope ('permissions' or 'allowed-tools') in its manifest but code uses detectable capabilities. Without a declaration, the skill's intent is opaque and cannot be validated.",
125125
"LP4": "Permission is declared but no corresponding code capability was detected. This may indicate removed functionality or pre-staging for future abuse.",
126126
# MCP Tool Poisoning (B.3.2)
127127
"TP1": "Hidden instructions detected in skill metadata (description, triggers, or parameters). These concealed directives can steer LLM behavior without the user's knowledge.",
@@ -380,7 +380,7 @@ class PatternCategory(StrEnum):
380380
# MCP Least Privilege (B.3.1)
381381
"LP1": "Add the missing permission to SKILL.md, or remove the code that requires it.",
382382
"LP2": "Replace wildcard permissions ('*', 'all', 'full', 'any') with an explicit list of required permissions.",
383-
"LP3": "Add a 'permissions' field to SKILL.md listing the capabilities this skill requires.",
383+
"LP3": "Declare the skill's tool scope: for Claude Code / Agent Skills SKILL.md, list the tools the skill may invoke in the 'allowed-tools' frontmatter field; for MCP server manifests, add a 'permissions' list naming the required capabilities.",
384384
"LP4": "Remove the declared permission if the corresponding capability is no longer used.",
385385
# MCP Tool Poisoning (B.3.2)
386386
"TP1": "Remove hidden content (HTML comments, markdown comments, zero-width characters, base64 blobs) from metadata fields. Metadata should contain plain, visible text only.",

0 commit comments

Comments
 (0)