Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 93% confidence
- Finding
- The skill markets itself as a persona/style adapter, but its documented behavior includes persistent local state creation, recurring cron scheduling, and ongoing access to session transcripts. That mismatch can defeat informed consent: a user may invoke it for tone adaptation without realizing it will continuously ingest chat history and maintain surveillance-like background processing.
