Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security checks across malware telemetry and agentic risk
This skill appears to do what it says: it fetches public currency exchange rates and converts amounts without accessing local files, credentials, or persistent state.
Install this if you are comfortable with currency lookup requests being sent to open.er-api.com. Ensure Python 3 and the requests package are available before using the scripts.
64/64 vendors flagged this skill as clean.