Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- 该技能明确要求将完整脚本写入会话目录并生成/删除多个本地文件,但未声明相应权限边界或最小化访问范围。权限与实际能力不透明会导致代理在用户不知情的情况下进行文件读写,若被误触发或被后续提示注入影响,可能造成会话文件被覆盖、持久化敏感内容或意外删除临时数据。
Security audit
Security checks across malware telemetry and agentic risk
The skill performs a disclosed feasibility-report review workflow that reads user-provided documents, searches external patent/paper/policy sources, and writes a local HTML report.
Install only if you are comfortable using PatSnap/MCP and web-search services with extracted information from the uploaded feasibility report. Avoid using confidential or unpublished project materials unless your organization allows that third-party processing.
65/65 vendors flagged this skill as clean.
No suspicious patterns detected.