Lp1
- Category
- MCP Least Privilege
- Confidence
- 75% confidence
- Finding
The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed, read-only LinkedIn data wrapper that sends user-requested queries to ScraperSocial and does not show hidden execution, file writes, or persistence.
Install only if you intend to use ScraperSocial for LinkedIn data and are comfortable providing a ScraperSocial API key. Because the skill can retrieve information about real people, including contact-related data, use it only with a lawful basis and avoid bulk personal-data collection where platform terms or privacy laws restrict it.
The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
The skill uses 'network' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
The skill uses 'shell' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
Detected: suspicious.env_credential_access