Undeclared Tool Scope
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
Without declared permissions the skill's intent is opaque and cannot be validated.
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This skill locally analyzes GitHub Actions run export files and does not show hidden network access, persistence, or destructive behavior.
Before installing, be aware that this skill will read whichever local GitHub Actions JSON files match RUN_GLOB and may print repository names, branches, SHAs, run URLs, and failure timing in its output. Keep RUN_GLOB scoped to the intended export directory if your workspace contains sensitive JSON files.
Without declared permissions the skill's intent is opaque and cannot be validated.
No suspicious patterns detected.