Tp4
- Category
- MCP Tool Poisoning
- Confidence
- 96% confidence
- Finding
The declared purpose says the skill should produce a project handoff and ready-to-paste prompt for a fresh session. The supplied code does not generate any handoff content. Instead, it reads a specified handoff file and project root, parses markdown headings, enforces required sections, checks size limits and placeholders, verifies prompt/path inclusion, and validates local link existence. This is a materially different primary purpose: validation of an already-written handoff, not reconciliation or authoring. No suspicious extra capability beyond local filesystem reads is present, but the core behavior does not match the declared description.
- Content
