Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 95% confidence
- Finding
- The declared purpose is a narrow API contract audit, but the analyzed behavior indicates a much broader, spec-driven scanning workflow including directory auditing, regex-based sensitive pattern scanning, CSV analysis, and package/frontmatter inspection. This mismatch is security-relevant because it can induce users or orchestrators to grant trust, data access, or execution rights appropriate for a small documentation checker while the skill actually processes a wider set of files and contexts.
