Undeclared Tool Scope
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
Without declared permissions the skill's intent is opaque and cannot be validated.
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a read-only changelog checker whose behavior matches its stated purpose.
Before installing, note that the skill runs a local Python script and reads the changelog file path you provide. It appears proportionate for changelog linting and does not show hidden persistence, network use, or data modification.
Without declared permissions the skill's intent is opaque and cannot be validated.
The manifest describes a skill for validating and linting CHANGELOG.md files against Keep a Changelog conventions. In addition to linting, the code exposes versions, order, and links commands that enumerate release metadata and perform targeted reporting, which goes beyond the narrowly described lint/validate interface.
No suspicious patterns detected.