Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 94% confidence
- Finding
- This second mismatch finding indicates the skill advertises CVE scanning with Trivy and structured reporting, while the actual behavior reportedly does not perform those actions. In a security-auditing skill, such misrepresentation is especially risky because users may treat a nonfunctional wrapper as an authoritative scanner and deploy insecure images or leave exposed secrets unaddressed.
