Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 90% confidence
- Finding
- The skill description emphasizes fetching quotes, but the documented setup flow also configures scheduled outbound delivery using chat/account context and filesystem-backed cron setup. That hidden operational behavior matters because it establishes persistence and outbound actions on behalf of the user, which can surprise users and expand risk beyond a simple quote lookup skill.
