Undeclared Tool Scope
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
Without declared permissions the skill's intent is opaque and cannot be validated.
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a local reporting tool that reads GitHub Actions JSON exports and calculates rerun waste without hidden network access, persistence, or destructive behavior.
Review the RUN_GLOB before use so it points only at intended GitHub Actions JSON exports. Collecting exports with gh may use your existing GitHub authentication, but the bundled script itself only reads local JSON files and prints text or JSON results.
Without declared permissions the skill's intent is opaque and cannot be validated.
No suspicious patterns detected.