Undeclared Tool Scope
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
Without declared permissions the skill's intent is opaque and cannot be validated.
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This is a documentation-only web crawling reference; it includes some anti-blocking advice to use cautiously, but I found no hidden execution, data collection, or persistence.
Install this as a reference skill only if you are comfortable with scraping guidance that includes anti-blocking techniques. Use it for lawful, permissioned crawling, prefer official APIs, follow site terms and robots.txt, and avoid using the proxy, fingerprint, CAPTCHA, or cookie-rotation advice to bypass a site's access controls.
Without declared permissions the skill's intent is opaque and cannot be validated.
Subtle instructions detected that may alter agent decision-making or introduce hidden biases.
- Always check ToS before scraping
## Ethical Scraping Guidelines
1. Check for API first (always prefer official API over scraping)
2. Read and follow robots.txt
3. Rate limit your requests (minimum 1s between requests per domain)
4. Identify your crawler (descriptive User-Agent with contact info)
The content explicitly recommends anti-detection measures such as rotating proxies, rotating headers, and varying TLS fingerprints to avoid blocking. In a web-scraping reference skill, this crosses from neutral education into operational guidance for evading site defenses, which can facilitate abusive or unauthorized scraping.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
//div[contains(@class,"x")] Class contains
//table/tr[position()>1] Skip header row
## curl with Cookie Jar
curl -c cookies.txt -b cookies.txt -L "https://example.com/login" -d "user=x&pass=y"
curl -b cookies.txt "https://example.com/data"
The FAQ gives step-by-step advice on how to avoid getting blocked, including rotating user agents, using residential proxies, matching browser fingerprints, and handling CAPTCHAs. That materially enables evasive scraping behavior and bypass of site-imposed defenses, making the skill more dangerous despite its reference-style framing.
No suspicious patterns detected.