Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a local multi-agent orchestration helper with a small local learning log, but no evidence of network exfiltration, destructive actions, or hidden automatic execution.
Install only if you are comfortable with a Chinese-language local CLI skill that can create or update learned_patterns.json files containing operation history, error notes, and preferences. Do not put secrets or sensitive personal data in learner notes or preference values.
No suspicious patterns detected.