Lp1
- Category
- MCP Least Privilege
- Confidence
- 75% confidence
- Finding
The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed read-only wrapper for ScraperSocial Kwai API lookups, with no evidence of hidden execution, persistence, or unrelated data access.
Before installing, understand that this uses your ScraperSocial API key and may spend API credits when looking up Kwai data. The reviewed artifacts are read-only and scoped to public Kwai lookups, but you should only use it if you are comfortable sending requested Kwai URLs or handles to ScraperSocial.
The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
The skill uses 'network' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
The skill uses 'shell' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
Detected: suspicious.env_credential_access