Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a local GitHub Actions failure-reporting helper that reads exported run JSON and prints matrix-focused summaries without hidden network, persistence, or credential behavior.
Install only if you are comfortable running a local Bash/Python reporting script over GitHub Actions JSON exports. Keep RUN_GLOB pointed at intended export files, because the script will read any matching local JSON paths you provide and may print repository names, branches, SHAs, job URLs, and failed step names from those files.
No suspicious patterns detected.