Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a local-only test agent that writes its own state files and prints dry-run proposal JSON, with no evidence of network use, credential access, publishing, or live chart mutation.
Install only if you want a local experimental agent loop that creates and updates files under its own state directory. Review generated state before using the dry-run proposal with any separate live-ingest or publishing tool.
permit persons to whom the Software is furnished to do so. THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. ClawHub distribution uses MIT-0. Lattice policy in references/SECURITY.md is not waived.
No suspicious patterns detected.