Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security checks across malware telemetry and agentic risk
This skill appears to be a straightforward local warehouse report generator that reads a chosen SQLite database and writes chart/report files.
Install only if you intend to run local Python report generation. Point --db at the intended warehouse database and --out at a safe output folder, since existing report files with the same names may be overwritten and generated files may contain business-sensitive data.
64/64 vendors flagged this skill as clean.