Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a local GitHub Actions report generator that reads exported run JSON and prints rerun effectiveness metrics without network access, persistence, or hidden privilege use.
Install only if you are comfortable letting the skill read the GitHub Actions JSON files matched by RUN_GLOB. Keep RUN_GLOB pointed at intended CI export directories because the script will parse any matching local JSON files and include selected run metadata in its report.
No suspicious patterns detected.