Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security checks across malware telemetry and agentic risk
This skill is a straightforward MCP server scaffold generator, with file-writing behavior that is expected for its purpose but should be used carefully.
Use this in a dedicated project directory, run with --dry-run first, avoid --allow-outside-workspace unless you intentionally need it, and do not set --output or scaffold_root to sensitive existing paths.
66/66 vendors flagged this skill as clean.