Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security audit
Security checks across malware telemetry and agentic risk
This skill locally converts a user-supplied X/Twitter bookmarks export into Markdown files, with no evidence of hidden network access, credential theft, or destructive behavior.
Install only if you are comfortable manually exporting your X/Twitter bookmark responses and storing the resulting Markdown files locally. Treat bookmarks.json and output/bookmarks/ as private data, review where the files are stored or synced, and be aware that very large bookmark collections can create many files.
| Type | What it exports | |------|---| | **Regular Tweet** | Full text, t.co URLs expanded, engagement stats, media links | | **Note Tweet** | Complete long-form text (no truncation) | | **X Article** | Title, preview text, article link | | **Quoted Tweet** | Original tweet + quoted tweet as blockquote |
4. Saves files to `output/bookmarks/` folder, named sequentially like `0001-title.md`. 5. Extracts full content for all tweet types: - **Regular tweets** — full text, t.co URLs expanded to real URLs - **Note tweets** — complete long-form text (no truncation) - **X Articles** — title + preview text + article link 6. Includes quoted tweets as blockquotes, media image/video links, and engagement stats.
63/63 vendors flagged this skill as clean.
No suspicious patterns detected.