Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a local GitHub Actions health reporting helper that reads exported run JSON and does not show hidden, persistent, destructive, or exfiltrating behavior.
Installers should understand that reports may include private repository names, workflow names, commit SHAs, and run URLs from the JSON files they provide. Use a narrow RUN_GLOB and review output before sharing it outside the organization.
No suspicious patterns detected.