Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a focused context-budgeting helper with disclosed local file reads, optional loopback tokenization, and safety guidance for user-directed instruction edits.
Install only if you want help auditing or reducing always-loaded instruction files. Treat any edits to agent instructions as high-impact changes, use the default redacted reports unless you intentionally need content shown, and only point the tokenizer option at a trusted local loopback service that does not retain requests.
reduce it without weakening authority, safety, or meaning. Use this skill when runtime logs report bootstrap truncation, per-turn context cost is high, policies appear in several files, or a persistent rule is being added. ## The two units differ
3. semantic and precedence review finds no weakened or unavailable rule; 4. all six assurance regressions pass; 5. before/after characters and tokens are recorded, with estimates labelled; 6. one fresh session runs without truncation or behaviour regressions; 7. temporary backups are securely removed after the clean-session gate.
No suspicious patterns detected.