Lp1
- Category
- MCP Least Privilege
- Confidence
- 75% confidence
- Finding
The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed, read-only Bluesky data wrapper that uses a ScraperSocial API key to query public Bluesky data.
Install only if you are comfortable giving this skill access to your ScraperSocial API key and using ScraperSocial credits for public Bluesky lookups. The inspected version appears read-only and limited to the documented ScraperSocial host and Bluesky endpoints.
The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
The skill uses 'network' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
The skill uses 'shell' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
This code accesses a sensitive credential from SCRAPERSOCIAL_KEY and sends it to a remote API using a Bearer token. Although the behavior is documented in developer comments, there is no user-facing disclosure such as a prompt, print statement, or runtime warning in this file.
Detected: suspicious.env_credential_access