Undeclared Tool Scope
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
Without declared permissions the skill's intent is opaque and cannot be validated.
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a local GitHub Actions reporting utility that reads run-export JSON files and does not show hidden network, credential, persistence, or destructive behavior.
Before installing, confirm you are comfortable running a local bash/python script against GitHub Actions run-export JSON. Keep RUN_GLOB pointed at intended export files, since the script will parse every matching JSON file and may include repository, workflow, branch, run ID, and run URL data in its reports.
Without declared permissions the skill's intent is opaque and cannot be validated.
No suspicious patterns detected.