Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 95% confidence
- Finding
- The skill description claims automatic nearby-hotel search and report generation, but the observed behavior includes manual data import and simulated auto-fetch behavior instead of the advertised functionality. This mismatch is dangerous because users and orchestrators may grant trust, permissions, or sensitive hotel data based on false assumptions about what the skill actually does, increasing the risk of inappropriate data handling and unsafe execution flows.
