Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly matches its stated research-reporting purpose, but its generated HTML report has an unsafe rendering pattern that could execute crafted input data in a browser.
Review before installing. Use it only for projects where SciMiner calls and possible input uploads are acceptable, keep SCIMINER_API_KEY out of project files, and open generated HTML reports only from trusted input data or after the renderer is patched to avoid innerHTML for table-derived metrics.
No suspicious patterns detected.