Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security audit
Security checks across malware telemetry and agentic risk
This skill has a clear medical reminder purpose, but it sends potentially identifiable health exam reports to a remote LLM while claiming de-identification that the code does not perform.
Review before installing if reports may contain names, IDs, phone numbers, dates, or other health information. Use only with reports that have already been de-identified, confirm the LLM endpoint and app key provider are approved for medical data, and avoid relying on the stated de-identification claim unless the code is changed to enforce it.
65/65 vendors flagged this skill as clean.
No suspicious patterns detected.