Undeclared Tool Scope
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
Without declared permissions the skill's intent is opaque and cannot be validated.
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed LinkDigest wrapper for analyzing user-provided social-media links, with the main privacy consideration that submitted links and results go to an external service.
Install only if you are comfortable sending submitted public links or share text to LinkDigest using your API key. Avoid private, deleted, login-only, or sensitive links because results may be cached by link; prefer the bundled Python script or curl path, and review/pin mcp-remote before using the optional npx MCP setup.
Without declared permissions the skill's intent is opaque and cannot be validated.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl -sS -X POST https://linkdigest.dev/api/v1/digest \
-H "Authorization: Bearer $LINKDIGEST_API_KEY" \
-H "Content-Type: application/json" \
-d '{"url": "https://v.douyin.com/<短链>/", "format": "json", "breakdown": true}'
The text states that Chinese breakdowns use a Chinese missing message while English breakdowns use an English message, and elsewhere the skill is primarily documented around Chinese defaults. This suggests a fixed language behavior path rather than consistently offering a user choice at output time, which can violate language/locale neutrality expectations.
The skill instructs users to run npx mcp-remote without pinning a package version or integrity, which can cause execution of a newer or compromised package from the npm registry. This creates a supply-chain risk because the fetched code runs locally and may access environment variables, network, or user data depending on the client context.
No suspicious patterns detected.