Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security audit
Security checks for vulnerabilities and agentic risk
This is a read-only dashboard skill whose stated MCP access matches its purpose, with some documentation gaps users should notice.
Install only in an environment where the configured dashboard-mcp server is trusted and the user is authorized to view operational and tenant data. Treat returned tenant, event, health, and agent-status results as potentially sensitive, and ask the publisher to clean up the stray Cookie-management sentence and add clearer data-handling guidance.
No suspicious patterns detected.