Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security audit
Security checks across malware telemetry and agentic risk
This skill fetches public GitHub Trending pages and formats trend reports without accessing private data, credentials, or persistent system settings.
Installers should understand that this skill runs local Python code and makes outbound requests to public GitHub pages. It does not appear to use private data or credentials, but its results depend on GitHub’s page structure and network availability.
66/66 vendors flagged this skill as clean.
No suspicious patterns detected.