Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security audit
Security checks across malware telemetry and agentic risk
This is a local signing tool, but its trusted-author labels can be misled by editable metadata, so users should review it before relying on it for security.
Use this only as a local utility until the trust-binding issue is fixed. Protect ~/.skillsign private keys, trust public keys only after verifying them independently, and do not treat TRUSTED labels, inspect output, or provenance chains as proof of author identity without additional verification.
66/66 vendors flagged this skill as clean.
No suspicious patterns detected.