Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 91% confidence
- Finding
- The skill’s declared purpose is limited to logging learnings, but the document also instructs agents to install hooks, write to multiple persistent context files, use inter-session tooling, and extract entirely new skills. That scope expansion matters because users or operators may grant it more trust than warranted, leading to unexpected persistence, broader prompt influence, and filesystem modification beyond simple note-taking.
