Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security checks across malware telemetry and agentic risk
This skill transparently downloads public DeBox documentation into a user-chosen folder and summarizes it, with behavior that matches its stated purpose.
Install this only if you want an agent to contact DeBox documentation pages and related documentation resources, then write a local mirror and summary. Choose a dedicated empty output folder, because the script manages files there and may remove stale files it previously recorded after a successful sync.
64/64 vendors flagged this skill as clean.