Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 92% confidence
- Finding
- The public description frames the skill as cloud advisory and AIOps assistance, but the instructions also authorize sensitive identity and control-plane actions such as OAuth token handling, local credential persistence, CAM role creation/deletion, STS role assumption, and passwordless login URL generation. This mismatch can cause users or orchestrators to invoke the skill without realizing it can manipulate IAM state and handle high-value credentials, increasing the chance of unsafe delegation.
