Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 89% confidence
- Finding
- The skill is presented as a generic comment-management utility, but the documentation shows it persistently stores arbitrary user inputs, maintains history/activity logs, supports search over past entries, and exports accumulated data. That expansion of behavior matters because users may invoke it with sensitive free-form content without realizing it will be retained locally and surfaced later via search, stats, or export features.
