Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security checks across malware telemetry and agentic risk
This is a local changelog linting skill that reads a user-selected changelog file and does not show hidden, network, credential, or persistence behavior.
Install this as a normal local linting helper. Run it only on changelog files you intend to inspect, and be careful enabling --strict in CI because warnings can block a build.
58/58 vendors flagged this skill as clean.