Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security checks across malware telemetry and agentic risk
This transcription skill is purpose-aligned, but it should be reviewed because it uploads audio and an API key to a configurable server while handling that server address unsafely.
Review before installing. Use only a WHISPER_API_HOST you trust, preferably a local or known server, because it receives the audio content and bearer token. Avoid sensitive audio until the host is quoted and validated and the skill adds clearer upload/privacy warnings.
65/65 vendors flagged this skill as clean.