Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 84% confidence
- Finding
- The skill description frames the behavior as simple secret scanning, but the documented commands also install git hooks and scan Docker images, which extends its operational reach and can modify repository state. This mismatch can mislead users and downstream policy systems into granting trust or permissions without realizing the skill can alter local git configuration and inspect additional assets.
