Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security audit
Security checks across malware telemetry and agentic risk
This skill is a straightforward QWeather lookup helper that runs a disclosed Python script and uses a QWeather API key for weather requests.
Install only if you are comfortable running the bundled Python script for QWeather lookups. Set QWEATHER_API_HOST to an official or trusted QWeather endpoint, protect the API key, and avoid passing the key in shared logs or transcripts.
65/65 vendors flagged this skill as clean.