Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 95% confidence
- Finding
- The skill is presented as a restaurant-booking tool, but the documentation authorizes a much broader telephony platform: activation, balance checks, inbound call handling, prompt reconfiguration, and generic outbound calling. This scope expansion can mislead users and reviewers into granting permissions and sharing data for a narrow use case while enabling substantially broader data access and communication capabilities.
