Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security audit
Security checks for vulnerabilities and agentic risk
This is a local todo manager that stores tasks in a user-confirmed local SQLite database, with no evidence of hidden network access, credential use, or destructive behavior.
Install only if you are comfortable with the skill creating a config file and a local SQLite todo database in the directory you confirm. The reference docs appear outdated, so rely on SKILL.md and the CLI behavior for the current SQLite-backed design.
No suspicious patterns detected.