Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security audit
Security checks for vulnerabilities and agentic risk
The skill locally analyzes a user-provided bank CSV for recurring subscriptions and does not show hidden network, persistence, credential, or file-writing behavior.
This skill appears safe to install for local CSV analysis, but bank transaction data is sensitive. Review results before acting on cancellation advice, especially where refunds, credits, or mixed debit/credit sign conventions may be present.
No suspicious patterns detected.