Lp3
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security audit
Security checks across malware telemetry and agentic risk
The skill broadly matches its Douyin automation purpose, but it grants persistent account-control and messaging authority with several under-scoped behaviors users should review first.
Install only on a dedicated machine or dedicated browser profile, and review bootstrap before running `--apply`. Expect it to control a Douyin account, send Feishu messages, read Feishu/Douyin interaction data, use configured LLM/video-provider credentials, and run persistent background jobs. Disable or inspect the local scheduler if you do not want automatic comment/private-message replies, and avoid exposing the daemon ports to a network.
VirusTotal findings are pending for this skill version.
Detected: suspicious.dangerous_exec, suspicious.dynamic_code_execution, suspicious.env_credential_access (+2 more)