Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security checks across malware telemetry and agentic risk
This skill is a local BPM helper whose file reads and command use match its stated tempo-analysis purpose.
Install if you want Codex to calculate BPM locally or analyze audio files you explicitly provide. For audio-file analysis, use a trusted ffmpeg installation and only pass file paths you are comfortable processing locally.
65/65 vendors flagged this skill as clean.