Tp4
- Category
- MCP Tool Poisoning
- Confidence
- 98% confidence
- Finding
The skill description omits that it performs authenticated external requests, local file and directory operations, workspace/environment discovery, identity creation/resolution, and token/login flows, while not implementing the promised plant-analysis pipeline. This combination of hidden identity, storage, and network behavior behind a benign gardening use case is especially dangerous because it can facilitate covert data collection and account linkage with low user suspicion.
- Content
