Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a local GitHub Actions failure-reporting utility whose file reads and script execution match its stated CI incident-audit purpose.
Install only if you are comfortable running a local bash/python script over GitHub Actions JSON exports. Review RUN_GLOB before use so it does not scan unrelated local JSON files, and use FAIL_ON_CRITICAL only when you want the script to fail CI on critical incidents.
No suspicious patterns detected.