Lp1
- Category
- MCP Least Privilege
- Confidence
- 75% confidence
- Finding
The skill uses 'network' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed DCC-MCP skill authoring helper that creates and validates skill packages without hidden persistence, credential use, or unrelated data access.
Install this only if you want an agent to create or modify local DCC-MCP skill package files. Review the target parent directory before using the scaffold tool, and use the pinned verified install procedure only with a commit ID from a trusted review record.
The skill uses 'network' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
skill-reference-docs:
- "references/*.md"
openclaw:
homepage: https://github.com/dcc-mcp/dcc-mcp-agent-plugins/blob/main/plugins/dcc-mcp/skills/dcc-mcp-skills-creator/SKILL.md
---
# DCC-MCP Skills Creator
The section titled 'Python 3.7 Policy' states that all authored skills must declare compatibility with Python 3.7+ when installed into certain hosts. This is a natural-language policy constraint that forces a specific runtime compatibility requirement broadly, without presenting it as an optional or user-selectable constraint in this document.
No suspicious patterns detected.