Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a straightforward Baidu Qianfan API toolbox, with expected remote API use and no evidence of hidden execution, persistence, or unrelated data access.
Install only if you are comfortable sending the text, search terms, document/image URLs, and generated-content requests you provide to Baidu Qianfan services using your BAIDU_API_KEY. Avoid using it with secrets, regulated personal data, or confidential internal documents unless that transfer is approved. Pinning axios and adding a lockfile would improve supply-chain reproducibility.
"author": "寇助理",
"license": "MIT",
"dependencies": {
"axios": "^1.6.0"
}
}No suspicious patterns detected.