Lp1
- Category
- MCP Least Privilege
- Confidence
- 75% confidence
- Finding
The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This skill appears to be a straightforward Naver search wrapper that uses one disclosed ScraperSocial API key and a fixed API host.
Before installing, understand that searches and your ScraperSocial API key are sent to ScraperSocial, and API usage may consume credits. The artifact does not show hidden local access or persistence beyond that disclosed API behavior.
The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
The skill uses 'network' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
The skill uses 'shell' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
Detected: suspicious.env_credential_access