Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security audit
Security checks across malware telemetry and agentic risk
The skill mostly matches its stated medical follow-up purpose, but it sends sensitive health report text to a remote model while promising de-identification that the code does not actually perform.
Review this carefully before installing. Use it only if you are comfortable sending health report contents to the configured LLM endpoint, and remove names, IDs, phone numbers, addresses, and other identifiers yourself because the script does not enforce the de-identification promised in the documentation.
65/65 vendors flagged this skill as clean.
No suspicious patterns detected.