Lp1
- Category
- MCP Least Privilege
- Confidence
- 75% confidence
- Finding
The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This is a disclosed API wrapper for public social and web data, with the contact-data endpoints visible for explanation but blocked from calls.
Before installing, understand that this can spend ScraperSocial credits and retrieve large amounts of public social/web data. Use it only for data you are authorized to collect, and note that contact-detail endpoints are intentionally not callable from this skill.
The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
The skill uses 'network' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
The skill uses 'shell' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
The skill metadata claims that personal-contact endpoints are excluded, but the endpoint catalog includes entries marked personalData=true, such as Google Maps contacts and LinkedIn contact-related capabilities. This mismatch can mislead downstream users, reviewers, or policy gates into enabling data-collection functionality they believed was absent, creating privacy, compliance, and trust risks.
The LinkedIn profile-contact endpoint explicitly exposes contact-oriented data while the skill description states that personal-contact endpoints are excluded. In a social-media scraping skill, that contradiction is especially dangerous because it increases the chance that operators will unintentionally collect personal data under false assumptions about the tool's scope.
The file includes Naver-specific endpoints and summaries, which implicitly target a Korean-language/locale ecosystem, but the manifest-style data provides no indication that this locale scope is optional or user-selected. Under the policy, forcing or assuming a specific language/locale without opt-in can be a natural-language policy concern when not clearly documented as region-specific.
Detected: suspicious.env_credential_access