Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security checks across malware telemetry and agentic risk
This skill is a disclosed Alibaba Cloud Milvus helper that performs expected vector database setup and search operations, with no artifact-backed signs of hidden or malicious behavior.
Install this only if you intend to let the agent access a Milvus instance. Use a least-privilege token, test against a non-production collection first, and avoid saving secrets or sensitive search results in the output evidence directory.
66/66 vendors flagged this skill as clean.