Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security audit
Security checks across malware telemetry and agentic risk
This skill locally analyzes user-provided OpenAI cost and usage JSON files and does not show hidden upload, credential, persistence, or destructive behavior.
Before installing, understand that you will be providing local OpenAI usage or cost exports to the agent for analysis. The artifact is designed to avoid API keys and uploads, but those exports may still contain project, model, request, or billing details, so only run it on files you are comfortable analyzing locally.
64/64 vendors flagged this skill as clean.
No suspicious patterns detected.