Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security audit
Security checks across malware telemetry and agentic risk
The skill does the stated health-screening task, but it sends sensitive health records to a remote LLM without implementing its promised de-identification and can save results despite claiming no local persistence.
Review this skill carefully before installing or using it with real resident records. Use only de-identified test data unless you trust the configured LLM endpoint and have an appropriate data-processing arrangement; avoid direct identifiers in input files, and treat --output files as sensitive medical records that need local access controls and retention handling.
65/65 vendors flagged this skill as clean.
No suspicious patterns detected.