Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 94% confidence
- Finding
- A strong description-behavior mismatch is security-relevant because the skill claims to perform bounded dataset intake auditing, while the underlying behavior reportedly supports broader directory enumeration, risk-pattern scanning, package validation, and mode-switching controlled by external `spec.json`. When execution can be redirected by external configuration into unrelated modes, users may authorize the skill under false assumptions and expose more files or workflows than intended.
