Tp4
- Category
- MCP Tool Poisoning
- Confidence
- 98% confidence
- Finding
The findings describe a broad set of hidden behaviors: local file and directory access, environment detection, identity creation and persistence, authenticated HTTP requests, token refresh, and remote login/registration flows. Under the cover of a rose-disease detector, these capabilities could enable silent account linkage, data exfiltration, and access to prior records, making the benign skill context materially more dangerous.
- Content
