Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security audit
Security checks across malware telemetry and agentic risk
The skill does what it advertises, but it handles sensitive medical reports in a way that deserves review before use.
Review this skill before installing in any environment that processes real patient reports. Use it only if the remote LLM endpoint is approved for your medical data, avoid including names or identifiers, and do not rely on the stated de-identification promise unless the implementation is changed to actually redact the report before sending.
60/60 vendors flagged this skill as clean.
No suspicious patterns detected.