Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 97% confidence
- Finding
- The declared purpose is narrow SBOM explanation, but the detected behavior appears to support broader directory scanning, data auditing, regex-based high-risk pattern scanning, and externally driven behavior from `spec.json`. This mismatch is dangerous because users and orchestrators may route sensitive inputs to the skill under a low-risk assumption, while the implementation can inspect unrelated files or perform broader analysis than expected.
