Lp1
- Category
- MCP Least Privilege
- Confidence
- 75% confidence
- Finding
The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed wrapper around ScraperSocial's Twitch public-data API and does not show hidden persistence, file writes, or credential misuse beyond using the documented API key.
Install this only if you are comfortable using ScraperSocial as a third-party provider for public Twitch lookups, spending its API credits, and exposing your ScraperSocial API key to these local Node scripts for requests to api.scrapersocial.com.
The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
The skill uses 'network' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
The skill uses 'shell' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
Detected: suspicious.env_credential_access