Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 98% confidence
- Finding
- The skill is presented as a dataset browsing/loading tool, but the documented behavior is primarily a local logging and history system that stores arbitrary user-provided inputs and exposes them via search, recent, status, and export commands. This mismatch is dangerous because users may provide sensitive dataset names, queries, paths, or processing details expecting data operations, while the skill instead persists and re-exposes that information without clear consent or minimization.
