Lp1
- Category
- MCP Least Privilege
- Confidence
- 75% confidence
- Finding
The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This is a disclosed read-only X/Twitter lookup skill that sends requested public-data queries and the ScraperSocial API key to ScraperSocial, with no hidden persistence or file mutation found.
Before installing, confirm you are comfortable using ScraperSocial as a third-party service for public X/Twitter lookups. Treat the API key as sensitive, and be aware that searches, handles, post URLs, and transcript or summary requests are sent to ScraperSocial and can consume account credits.
The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
The skill uses 'network' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
The skill uses 'shell' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
Detected: suspicious.env_credential_access