Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security audit
Security checks across malware telemetry and agentic risk
This skill performs a disclosed local memory-review workflow with constrained reads and writes, and I did not find hidden network, credential, destructive, or unrelated behavior.
Install this only for workspaces where the agent is allowed to review daily memory logs and update canonical memory files. Review generated decision plans and diffs before accepting changes, especially because memory files may contain sensitive operational context.
64/64 vendors flagged this skill as clean.
Detected: suspicious.dynamic_code_execution