Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 92% confidence
- Finding
- The skill instructs the agent to read database credentials from a local config file and write queried order data to local storage, yet no permissions are declared. In a permissive runtime, this can lead to unauthorized access to sensitive business data or credential handling beyond what the user reasonably expects from the manifest.
