Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security checks across malware telemetry and agentic risk
This skill is a local CAD helper that reads a user-provided JSON design file and writes DXF/SVG output files, with no evidence of hidden network, credential, persistence, or destructive behavior.
Install only if you are comfortable running a local Python renderer that creates CAD files in an output directory you choose. Follow the SKILL.md command path, scripts/create_dxf.py, not the stale rfq_cad.py reference, and manually verify dimensions and geometry before sending generated files for quoting or fabrication.
64/64 vendors flagged this skill as clean.