Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security audit
Security checks for vulnerabilities and agentic risk
This skill coherently post-processes official web fetch results and does not show hidden execution, exfiltration, persistence, or destructive behavior.
Users should be comfortable allowing this skill to process fetched page content and run a local Node script. For stronger supply-chain control, install from a reviewed lockfile or pin the turndown dependency before use.
{"type":"module","dependencies":{"turndown":"^7.2.2"}}No suspicious patterns detected.