Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security audit
Security checks across malware telemetry and agentic risk
This skill is a disclosed medical-record quality check tool, but users should handle it as sensitive because it sends record fields to an external LLM endpoint.
Use this only with records that have already been de-identified, confirm the configured LLM endpoint is acceptable for your privacy and compliance requirements, keep the appkey out of repositories and logs, and avoid --save-prepared unless you are prepared to store sensitive preprocessed record text locally.
65/65 vendors flagged this skill as clean.
No suspicious patterns detected.