Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security audit
Security checks across malware telemetry and agentic risk
The skill mainly does what it claims, but it has under-described access to account knowledge-base data and writes a local project cache outside its declared write paths.
Install only if you are comfortable uploading tender and bid documents to the 百炼®标书 cloud service and having results retained under the API-key account. Be aware that the skill can query account knowledge-base data and can leave local metadata in ~/.zcm/projects.json in addition to the skill-local config.json API key and generated output files.
65/65 vendors flagged this skill as clean.
No suspicious patterns detected.