Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a local GitHub Actions report generator that reads exported run JSON and prints duplicate-run analysis without hidden network access, credential use, persistence, or destructive behavior.
Installers should be aware that the tool can read whatever local files match RUN_GLOB and may print repository names, branches, commits, run URLs, and timing metadata in reports. Keep RUN_GLOB scoped to intended GitHub Actions JSON exports, especially in shared CI logs.
No suspicious patterns detected.