# permission-creep-scanner

> Use this tool when you need to detect unauthorized access to resources by AI agent skills, helping to identify and prevent permission creep. It scans skill code to flag instances where actual resource access exceeds intended permissions, ensuring secure and compliant skill development. Input includes AI agent skill code, with outputs highlighting potential security vulnerabilities and areas for permission refinement.

Canonical page: https://skillsregistry.net/skills/andyxinweiminicloud-permission-creep-scanner  
JSON: https://api.skillsregistry.net/v1/skills/andyxinweiminicloud-permission-creep-scanner

## Description

Helps detect permission creep in AI agent skills — flags when a skill's actual code accesses resources far.

## Trust

- **Trust score (0–1):** 0.65
- **Verification tier:** scanned
- **Last scanned:** 2026-05-21

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** instructions
- **Runtime environment:** llm
- **Category:** ai-ml
- **Updated:** 2026-05-21

## Source

- **Source listing:** [ClawHub](https://clawskills.sh/skills/andyxinweiminicloud-permission-creep-scanner)

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "andyxinweiminicloud-permission-creep-scanner"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/andyxinweiminicloud-permission-creep-scanner` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/andyxinweiminicloud-permission-creep-scanner/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
