Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 96% confidence
- Finding
- The skill advertises a bounded self-improvement system, but the described behavior extends to external evaluator calls, prompt-context injection, and script copying without clear disclosure in the top-level purpose or permissions narrative. This is dangerous because operators may approve a skill they believe is local and constrained, while it can transmit session-derived data externally, alter agent context, and persist new executable content in the workspace.
