Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed Qixin enterprise risk lookup client, with expected external API use and no hidden persistence, exfiltration, or destructive behavior found.
Install only if you intend to send company names or enterprise IDs to Qixin using your QXBENT_API_TOKEN. For important diligence decisions, prefer an exact enterprise ID and confirm that the returned ename is the company you meant to query. Review resolved npm dependency versions during install because the package does not include a lockfile.
"author": "",
"license": "MIT",
"dependencies": {
"axios": "^1.6.0"
},
"devDependencies": {
"@types/node": "^20.0.0","axios": "^1.6.0"
},
"devDependencies": {
"@types/node": "^20.0.0",
"ts-node": "^10.9.0",
"typescript": "^5.0.0"
}},
"devDependencies": {
"@types/node": "^20.0.0",
"ts-node": "^10.9.0",
"typescript": "^5.0.0"
}
}"devDependencies": {
"@types/node": "^20.0.0",
"ts-node": "^10.9.0",
"typescript": "^5.0.0"
}
}No suspicious patterns detected.