Tp4
- Category
- MCP Tool Poisoning
- Confidence
- 96% confidence
- Finding
Automatic identity creation/reuse, local token/file handling, remote login, and injection of authentication headers into requests are highly sensitive behaviors not suggested by the user-facing description. In this context, the mismatch is more dangerous because the skill handles uploaded media and historical reports, so hidden account-linkage and token persistence can silently expand access to user data and remote services.
- Content
