Lp3
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security audit
Security checks across malware telemetry and agentic risk
The skill mostly matches its restaurant lookup and queueing purpose, but it includes an under-disclosed Meituan signing component that creates a persistent local device identifier outside the documented token directory.
Review before installing if you are uncomfortable with local account authorization helpers. Public restaurant lookups are scoped, but queue features use Meituan authorization, store a token under ~/.jinguyuan, spawn a short-lived background auth poller, and the signing dependency also creates a persistent ~/.cliguard device identifier that the skill does not clearly disclose. Only proceed if you trust the publisher and understand that confirmed take-number/cancel actions affect a real queue account.
VirusTotal findings are pending for this skill version.
Detected: suspicious.dangerous_exec, suspicious.obfuscated_code