Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security checks across malware telemetry and agentic risk
This skill is a focused local reporting tool that reads GitHub Actions run JSON files and reports rerun waste without network access, persistence, or credential handling.
Install this if you want a local CI rerun-waste report. Before running it, point RUN_GLOB only at GitHub Actions exports you intend to analyze, and avoid publishing the generated output if repository names, branches, commit SHAs, run IDs, or job URLs are sensitive.
59/59 vendors flagged this skill as clean.