Lp1
- Category
- MCP Least Privilege
- Confidence
- 75% confidence
- Finding
The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed, read-only TikTok data wrapper that sends user-requested public-data queries to ScraperSocial and does not show hidden persistence, local data access, or account-changing behavior.
Before installing, understand that each call sends your ScraperSocial API key and the requested TikTok URL, handle, query, cursor, or related parameters to ScraperSocial and may spend credits. Use it for public TikTok research only, and avoid broad follower/comment collection unless you intentionally want that cost and data volume.
The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
The skill uses 'network' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
The skill uses 'shell' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
Detected: suspicious.env_credential_access