Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a local GitHub Actions report generator that reads exported run JSON and prints reliability rankings without hidden network, credential, persistence, or mutation behavior.
Before installing, expect the skill to process GitHub Actions run exports that may include repository names, actor logins, branch names, events, run URLs, and failure history. Keep RUN_GLOB pointed at the intended export directory and review JSON output before using FAIL_ON_CRITICAL as an automated gate.
No suspicious patterns detected.