Lp1
- Category
- MCP Least Privilege
- Confidence
- 75% confidence
- Finding
The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed App Store data client that uses a ScraperSocial API key to fetch public App Store information.
Install this only if you are comfortable using ScraperSocial as a third-party service and sending your ScraperSocial API key to `api.scrapersocial.com`. The scripts may consume ScraperSocial credits when called, but the reviewed artifact does not show hidden persistence, local data collection, or unrelated network destinations.
The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
The skill uses 'network' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
The skill uses 'shell' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
Detected: suspicious.env_credential_access