Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security audit
Security checks across malware telemetry and agentic risk
This medical referral skill is purpose-aligned, but needs Review because it sends patient summaries to a remote LLM while promising de-identification that the code does not perform.
Review before installing. Use only with patient summaries that have already been de-identified, verify that the remote LLM endpoint and app key handling meet your privacy and medical compliance requirements, and be aware that optional output files may contain sensitive medical content.
63/63 vendors flagged this skill as clean.
No suspicious patterns detected.