Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security audit
Security checks across malware telemetry and agentic risk
This skill helps sanitize public GitHub contributions and requires explicit approval before posting or editing anything public.
Before installing, understand that this skill is designed for public GitHub work: only approve publication after reviewing the exact draft, destination, identity, attachments, and fetched public result. Keep deny-term files private and do not rely on the scanner alone for sensitive disclosures.
65/65 vendors flagged this skill as clean.
Detected: suspicious.dynamic_code_execution