Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 91% confidence
- Finding
- The documented behavior does not fully match the reported code capabilities: auto-sync/cron setup, extra version-listing aliases, and syncing/restoring custom skills materially expand the attack surface beyond a simple memory backup tool. Hidden or under-disclosed behaviors are dangerous because users may authorize a 'secure sync' skill without realizing it can persist scheduled jobs or overwrite executable skill content, enabling stealthy persistence or supply-chain style compromise.
