Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 93% confidence
- Finding
- The skill's high-level description frames the behavior as MBTI analysis and visualization, but the implementation materially expands scope by recursively scanning `~/.openclaw/`, aggregating conversation history, and opening an external site with derived profile data. This mismatch undermines informed consent because users may not realize the skill reads all local chat archives and exports derived personal data into a browser context.
