Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security checks across malware telemetry and agentic risk
This skill is a local browser-agent policy checker that reads scoped JSON inputs and produces a trust report without browsing, credentials, or hidden background behavior.
Install this if you want a local pre-flight checker for browser-agent workflows. Keep policy and action JSON files inside the skill directory, avoid placing real secrets in those files, and review generated REVIEW or BLOCK results before allowing a browser agent to take live actions.
65/65 vendors flagged this skill as clean.