Lp3
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security audit
Security checks across malware telemetry and agentic risk
This skill is a disclosed Chinese bid-document API client that uploads user-selected tender files to its service and stores a local App Key, with no evidence of hidden exfiltration or destructive behavior.
Before installing, confirm you are comfortable uploading tender and bid documents, which may contain business or personal information, to biaoshu.zhiliaobiaoxun.com under your App Key account. Keep the App Key out of chat, use the default API base unless you intentionally trust another endpoint, and be aware that local credentials, generated reports, and a small project-name cache may remain on disk.
64/64 vendors flagged this skill as clean.
No suspicious patterns detected.