Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security checks across malware telemetry and agentic risk
This is a local Composer composer.json linter that reads a user-selected file and reports validation issues without network access, credential use, persistence, or file mutation.
Install if you are comfortable running a bundled Python script against Composer files you choose. Use --strict only when warning-level findings should fail automation, and review output before relying on it in CI.
66/66 vendors flagged this skill as clean.