Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security audit
Security checks across malware telemetry and agentic risk
This skill locally summarizes ActivityWatch computer-usage data and its sensitive access is disclosed, scoped, and aligned with that purpose.
Before installing, understand that this skill is meant to read local computer-activity records and can reveal sensitive work patterns and window-title context. Keep ActivityWatch local, review any saved CSV/TSV reports before sharing them, and only provide browser history, recent documents, terminal history, or Screen Time totals when you intentionally want those sources used.
title is `confirmed` only when it directly supports the described activity. 5. When the user needs project/client or billable reporting, offer an optional local JSON `--rules` file. Match only sanitized titles. Explain that the first matching rule wins and never create or upload rules without consent. 6. For spreadsheet output, run one table per command: - `--format markdown --table apps` for chat. - `--format tsv --table apps` to copy directly into spreadsheet software.
65/65 vendors flagged this skill as clean.
No suspicious patterns detected.