Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security audit
Security checks for vulnerabilities and agentic risk
This skill does what it says: it signs Nostr login challenges using a local key and only sends results to a user-specified callback.
Before installing, understand that this creates or uses an agent Nostr identity stored in a local master key file and can authenticate to services when given a challenge and callback. Use dry-run first, verify callback URLs, and do not pass a valuable personal Nostr private key unless you intend this tool to use that identity.
Detected: suspicious.exposed_secret_literal