Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 93% confidence
- Finding
- The skill's declared purpose is UI design guidance, but the documented behavior includes modifying a workspace configuration file and adding static rules that may influence future agent behavior. This creates a trust and transparency problem: users may invoke a design skill expecting advisory output, while it instead changes persistent project state in ways unrelated to the advertised capabilities.
