Lp3
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security audit
Security checks across malware telemetry and agentic risk
The skill openly targets device and social-account automation, but its broad control over messages, posts, apps, screenshots, and self-learning state needs careful review before installation.
Install only if you intentionally want an external MCP server to control Android devices and social accounts. Before use, inspect the MCP server implementation and config, restrict it to test devices or limited accounts, require explicit confirmation before sending messages, publishing content, installing apps, receiving funds, or taking screenshots, and review how screenshots, cookies, account data, and self-learning records are stored and deleted.
VirusTotal findings are pending for this skill version.
No suspicious patterns detected.