Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 97% confidence
- Finding
- The skill is presented as a habit-tracking tool, but the documented interface is a generic data-processing and logging utility with commands unrelated to habits, reminders, or streaks. This kind of description-behavior mismatch is dangerous because it can trick users or agents into invoking capabilities they did not intend to trust, including broad ingestion, querying, exporting, and profiling of local data.
