Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security audit
Security checks across malware telemetry and agentic risk
This appears to be a legitimate API gateway skill, but it needs review because it stores API keys locally and can send them to user-supplied endpoints with weak safeguards.
Review before installing. Use this only for API calls you intentionally route through it, avoid entering real secrets directly on the command line, and assume keys and cached API responses may remain on disk. Be especially careful with custom or unknown providers because the gateway may attach a bearer token to a user-supplied URL after only a warning.
## Security Notes - Keys stored as plain text in JSON (same risk as .env files) - For production, integrate with a secrets manager - Masked output prevents accidental exposure in logs - Request log limited to 1000 entries
VirusTotal findings are pending for this skill version.
No suspicious patterns detected.