Tp4
- Category
- MCP Tool Poisoning
- Confidence
- 99% confidence
- Finding
Authentication handling, token/header injection, automatic remote login or user creation, local workspace discovery, and persistent default identity generation are all high-risk behaviors when hidden behind a simple seed-counting skill. This combination can silently bind user activity to remote accounts, expose local environment structure, and expand the blast radius of compromise or misuse.
- Content
