Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security checks across malware telemetry and agentic risk
This appears to be a disclosed web-browsing and research helper using Tabstack, with no artifact-backed evidence of malware or hidden persistence.
Install only if you are comfortable routing web research tasks through Tabstack and providing the required API key. Be careful with private URLs, confidential PDFs, or sensitive queries, and consider pinning dependency versions for more reproducible installs.
"private": true,
"description": "OpenClaw skill for web browsing via the Tabstack API",
"dependencies": {
"@tabstack/sdk": "^2.2.0",
"tsx": "^4.0.0"
}
}"description": "OpenClaw skill for web browsing via the Tabstack API",
"dependencies": {
"@tabstack/sdk": "^2.2.0",
"tsx": "^4.0.0"
}
}66/66 vendors flagged this skill as clean.