Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 94% confidence
- Finding
- The manifest and description present the skill as a boiler efficiency and sizing tool, but the documented commands describe a generic local datastore that can add, search, remove, export, and configure arbitrary records. This mismatch can mislead users and reviewers about the real behavior of the skill, reducing informed consent and making it easier to smuggle unexpected data-handling functionality into an apparently domain-specific tool.
