Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 93% confidence
- Finding
- The skill is presented as an illustration generator/converter, but it also instructs the agent to extract embedded SVGs from user articles and persist them under an internal archive directory. That creates undisclosed data retention and secondary processing of user content, which exceeds the stated purpose and can expose sensitive article content, metadata, or embedded comments to future access.
