Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a local reporting utility that reads exported GitHub Actions run JSON and does not show hidden network, credential, persistence, or destructive behavior.
Before installing, confirm you are comfortable running a local bash/python script over your GitHub Actions run exports. Review or constrain RUN_GLOB if the working directory contains unrelated JSON files, especially if you customize it beyond the default path.
No suspicious patterns detected.