Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security checks across malware telemetry and agentic risk
This skill is a local SWMM model builder that reads user-provided hydrology files and writes model outputs, with no hidden network, credential, persistence, or destructive behavior found.
Install this if you want a local SWMM INP assembly helper. Before running it, review the input and output paths because the script can read those local files and write or overwrite the requested output files; no evidence shows hidden data collection or automatic execution.
63/63 vendors flagged this skill as clean.